Lenovo update for NVIDIA ConnectX



Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2024-0105
CVE-2024-0106
CWE-ID CWE-264
Exploitation vector Local network
Public exploit N/A
Vulnerable software
ThinkSystem SR950 V3
Hardware solutions / Firmware

ThinkSystem SR950
Hardware solutions / Firmware

ThinkSystem SR860
Hardware solutions / Firmware

ThinkSystem SR850P
Hardware solutions / Firmware

ThinkSystem SR850
Hardware solutions / Firmware

ThinkSystem SR680a V3
Hardware solutions / Firmware

ThinkSystem SR675 V3
Hardware solutions / Firmware

ThinkSystem SR670
Hardware solutions / Firmware

ThinkSystem SR665 V3
Hardware solutions / Firmware

ThinkSystem SR655 V3
Hardware solutions / Firmware

ThinkSystem SR650
Hardware solutions / Firmware

ThinkSystem SR645 V3
Hardware solutions / Firmware

ThinkSystem SR635 V3
Hardware solutions / Firmware

ThinkSystem SR630 V4
Hardware solutions / Firmware

ThinkSystem SR630
Hardware solutions / Firmware

ThinkSystem SD650 DWC Dual Node Tray
Hardware solutions / Firmware

ThinkSystem SD550 V3
Hardware solutions / Firmware

ThinkSystem SD535 V3
Hardware solutions / Firmware

ThinkSystem SD530 V3
Hardware solutions / Firmware

ThinkServer SR860P
Hardware solutions / Firmware

ThinkEdge SE455 V3
Hardware solutions / Firmware

ThinkAgile VX7820
Hardware solutions / Firmware

ThinkAgile VX7575 Integrated System
Hardware solutions / Firmware

ThinkAgile VX7531 Certified Node
Hardware solutions / Firmware

ThinkAgile VX7530 Appliance
Hardware solutions / Firmware

ThinkAgile VX7520 N
Hardware solutions / Firmware

ThinkAgile VX7520
Hardware solutions / Firmware

ThinkAgile VX7375-N Integrated System
Hardware solutions / Firmware

Thinkagile VX7330 Appliance
Hardware solutions / Firmware

ThinkAgile VX7320 N
Hardware solutions / Firmware

ThinkAgile VX650 V2 DPU Certified Node
Hardware solutions / Firmware

ThinkAgile VX5530 Appliance
Hardware solutions / Firmware

ThinkAgile VX5520
Hardware solutions / Firmware

ThinkAgile VX3720
Hardware solutions / Firmware

ThinkAgile VX3575-G Integrated System
Hardware solutions / Firmware

ThinkAgile VX3530-G Appliance
Hardware solutions / Firmware

ThinkAgile VX3520-G
Hardware solutions / Firmware

ThinkAgile VX3376 Certified Node
Hardware solutions / Firmware

ThinkAgile VX3375 Integrated System
Hardware solutions / Firmware

ThinkAgile VX3330 Appliance
Hardware solutions / Firmware

ThinkAgile VX3320
Hardware solutions / Firmware

ThinkAgile VX2375 Integrated System
Hardware solutions / Firmware

ThinkAgile VX2330 Appliance
Hardware solutions / Firmware

ThinkAgile VX2320
Hardware solutions / Firmware

ThinkAgile VX1320
Hardware solutions / Firmware

ThinkAgile VX 4U Certified Node
Hardware solutions / Firmware

ThinkAgile VX 2U4N Certified Node
Hardware solutions / Firmware

ThinkAgile VX 2U Certified Node
Hardware solutions / Firmware

ThinkAgile VX 1U Certified Node
Hardware solutions / Firmware

ThinkAgile VX 1SE Certified Node
Hardware solutions / Firmware

ThinkAgile MX650 V3 Premier System
Hardware solutions / Firmware

ThinkAgile MX650 v3 Integrated System
Hardware solutions / Firmware

ThinkAgile MX650 V3 Certified Node
Hardware solutions / Firmware

ThinkAgile MX630 V3 Integrated System
Hardware solutions / Firmware

ThinkAgile MX630 V3 Certified Node
Hardware solutions / Firmware

ThinkAgile MX3531-F All-flash Certified node
Hardware solutions / Firmware

ThinkAgile MX3531 H Hybrid Certified node
Hardware solutions / Firmware

ThinkAgile MX3530-H Hybrid Appliance
Hardware solutions / Firmware

ThinkAgile MX3530 F All flash Appliance
Hardware solutions / Firmware

ThinkAgile MX3520 H Appliance - Hybrid
Hardware solutions / Firmware

ThinkAgile MX3520 F Appliance - All flash
Hardware solutions / Firmware

ThinkAgile MX Edge Appliance - MX1020
Hardware solutions / Firmware

ThinkAgile HX7821 Certified Node
Hardware solutions / Firmware

ThinkAgile HX7820 Appliance
Hardware solutions / Firmware

ThinkAgile HX7531 Certified Node
Hardware solutions / Firmware

ThinkAgile HX7521 Certified Node
Hardware solutions / Firmware

ThinkAgile HX7520 Appliance
Hardware solutions / Firmware

ThinkAgile HX5531 Certified Node
Hardware solutions / Firmware

ThinkAgile HX5521-C Certified Node
Hardware solutions / Firmware

ThinkAgile HX5521 Certified Node
Hardware solutions / Firmware

ThinkAgile HX5520-C Appliance
Hardware solutions / Firmware

ThinkAgile HX5520 Appliance
Hardware solutions / Firmware

ThinkAgile HX3521-G Certified Node
Hardware solutions / Firmware

ThinkAgile HX3520-G Appliance
Hardware solutions / Firmware

ThinkAgile HX3331 Certified Node
Hardware solutions / Firmware

ThinkAgile HX3330 Appliance
Hardware solutions / Firmware

ThinkAgile HX3321 Certified Node
Hardware solutions / Firmware

ThinkAgile HX3320 Appliance
Hardware solutions / Firmware

ThinkAgile HX2331 Certified Node
Hardware solutions / Firmware

ThinkAgile HX2330 Appliance
Hardware solutions / Firmware

ThinkAgile HX2321 Certified Node
Hardware solutions / Firmware

ThinkAgile HX2320-E Appliance
Hardware solutions / Firmware

ThinkAgile HX2320 Appliance
Hardware solutions / Firmware

ThinkAgile HX1521-R Certified Node
Hardware solutions / Firmware

ThinkAgile HX1520-R Appliance
Hardware solutions / Firmware

ThinkAgile HX1331 Certified Node
Hardware solutions / Firmware

ThinkAgile HX1330 Appliance
Hardware solutions / Firmware

ThinkAgile HX1321 Certified Node
Hardware solutions / Firmware

ThinkAgile HX1320 Appliance
Hardware solutions / Firmware

ThinkAgile VX3331 Certified Node
Hardware solutions / Firmware

ThinkAgile HX7530 Appliance
Hardware solutions / Firmware

ThinkAgile HX5530 Appliance
Hardware solutions / Firmware

System x3950 X6
Hardware solutions / Firmware

System x3850 X6
Hardware solutions / Firmware

System x3750 M4
Hardware solutions / Firmware

System x3650 M5
Hardware solutions / Firmware

System x3500 M5
Hardware solutions / Firmware

Flex Compute Node - x880 X6
Hardware solutions / Firmware

Flex Compute Node - x480 X6
Hardware solutions / Firmware

Flex Compute Node - x280 X6
Hardware solutions / Firmware

Flex Compute Node - x240 M5
Hardware solutions / Firmware

NeXtScale Compute Node - nx360 M5
Hardware solutions / Firmware

ThinkSystem ST658 V3
Hardware solutions / Firmware

ThinkSystem ST658 V2
Hardware solutions / Firmware

ThinkSystem ST650 V3
Hardware solutions / Firmware

ThinkSystem ST650 V2
Hardware solutions / Firmware

ThinkSystem ST558
Hardware solutions / Firmware

ThinkSystem ST550
Hardware solutions / Firmware

ThinkSystem SR860 V3
Hardware solutions / Firmware

ThinkSystem SR860 V2
Hardware solutions / Firmware

ThinkSystem SR850 V3
Hardware solutions / Firmware

ThinkSystem SR850 V2
Hardware solutions / Firmware

ThinkSystem SR670 V2
Hardware solutions / Firmware

ThinkSystem SR650 V3
Hardware solutions / Firmware

ThinkSystem SR630 V3
Hardware solutions / Firmware

ThinkSystem SR630 V2
Hardware solutions / Firmware

ThinkSystem SR258
Hardware solutions / Firmware

ThinkSystem SR250
Hardware solutions / Firmware

ThinkSystem SN850
Hardware solutions / Firmware

ThinkSystem SN550 V2
Hardware solutions / Firmware

ThinkSystem SN550
Hardware solutions / Firmware

ThinkSystem SE350
Hardware solutions / Firmware

ThinkSystem SD650-N V2
Hardware solutions / Firmware

ThinkSystem SD650 V2
Hardware solutions / Firmware

ThinkSystem SD630 V2
Hardware solutions / Firmware

ThinkSystem SD530
Hardware solutions / Firmware

ThinkAgile MX1021 on SE350
Hardware solutions / Firmware

ThinkAgile MX Certified Node – Hybrid
Hardware solutions / Firmware

ThinkAgile MX Certified Node – All Flash
Hardware solutions / Firmware

ThinkAgile MX3331-H Hybrid Certified node
Hardware solutions / Firmware

ThinkAgile MX3331-F All-flash Certified node
Hardware solutions / Firmware

ThinkAgile MX3330-H Hybrid Appliance
Hardware solutions / Firmware

ThinkAgile MX3330-F All-flash Appliance
Hardware solutions / Firmware

ThinkAgile HX3721 Certified Node
Hardware solutions / Firmware

ThinkAgile HX3720 Appliance
Hardware solutions / Firmware

ThinkAgile HX2720-E Appliance
Hardware solutions / Firmware

System x3550 M5
Hardware solutions / Firmware

ThinkSystem SR650 V2
Hardware solutions / Firmware

ThinkEdge SE450
Hardware solutions / Firmware

ThinkSystem SR665
Hardware solutions / Firmware

ThinkSystem SR655
Hardware solutions / Firmware

ThinkSystem SR645
Hardware solutions / Firmware

ThinkSystem SR635
Hardware solutions / Firmware

Nvidia-Mellanox ConnectX Networking Adapter/Device VMware Driver
Hardware solutions / Drivers

Nvidia-Mellanox ConnectX Networking Adapter/Device Linux Firmware
Hardware solutions / Drivers

Nvidia-Mellanox ConnectX Networking Adapter/Device Windows Firmware
Hardware solutions / Drivers

Nvidia-Mellanox ConnectX Networking Adapter/Device Windows Driver
Hardware solutions / Drivers

Vendor Lenovo

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU99496

Risk: Medium

CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2024-0105

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote user on the local network to compromise the target system.

The vulnerability exists due to improper handling of insufficient privileges, which leads to denial of service, data tampering and limited information disclosure.

Mitigation

Install update from vendor's website.

Vulnerable software versions

ThinkSystem SR950 V3: All versions

ThinkSystem SR950: All versions

ThinkSystem SR860: All versions

ThinkSystem SR850P: All versions

ThinkSystem SR850: All versions

ThinkSystem SR680a V3: All versions

ThinkSystem SR675 V3: All versions

ThinkSystem SR670: All versions

ThinkSystem SR665 V3: All versions

ThinkSystem SR655 V3: All versions

ThinkSystem SR650: All versions

ThinkSystem SR645 V3: All versions

ThinkSystem SR635 V3: All versions

ThinkSystem SR630 V4: All versions

ThinkSystem SR630: All versions

ThinkSystem SD650 DWC Dual Node Tray: All versions

ThinkSystem SD550 V3: All versions

ThinkSystem SD535 V3: All versions

ThinkSystem SD530 V3: All versions

ThinkServer SR860P: All versions

ThinkEdge SE455 V3: All versions

ThinkAgile VX7820: All versions

ThinkAgile VX7575 Integrated System: All versions

ThinkAgile VX7531 Certified Node: All versions

ThinkAgile VX7530 Appliance: All versions

ThinkAgile VX7520 N: All versions

ThinkAgile VX7520: All versions

ThinkAgile VX7375-N Integrated System: All versions

Thinkagile VX7330 Appliance: All versions

ThinkAgile VX7320 N: All versions

ThinkAgile VX650 V2 DPU Certified Node: All versions

ThinkAgile VX5530 Appliance: All versions

ThinkAgile VX5520: All versions

ThinkAgile VX3720: All versions

ThinkAgile VX3575-G Integrated System: All versions

ThinkAgile VX3530-G Appliance: All versions

ThinkAgile VX3520-G: All versions

ThinkAgile VX3376 Certified Node: All versions

ThinkAgile VX3375 Integrated System: All versions

ThinkAgile VX3330 Appliance: All versions

ThinkAgile VX3320: All versions

ThinkAgile VX2375 Integrated System: All versions

ThinkAgile VX2330 Appliance: All versions

ThinkAgile VX2320: All versions

ThinkAgile VX1320: All versions

ThinkAgile VX 4U Certified Node: All versions

ThinkAgile VX 2U4N Certified Node: All versions

ThinkAgile VX 2U Certified Node: All versions

ThinkAgile VX 1U Certified Node: All versions

ThinkAgile VX 1SE Certified Node: All versions

ThinkAgile MX650 V3 Premier System: All versions

ThinkAgile MX650 v3 Integrated System: All versions

ThinkAgile MX650 V3 Certified Node: All versions

ThinkAgile MX630 V3 Integrated System: All versions

ThinkAgile MX630 V3 Certified Node: All versions

ThinkAgile MX3531-F All-flash Certified node: All versions

ThinkAgile MX3531 H Hybrid Certified node: All versions

ThinkAgile MX3530-H Hybrid Appliance: All versions

ThinkAgile MX3530 F All flash Appliance: All versions

ThinkAgile MX3520 H Appliance - Hybrid: All versions

ThinkAgile MX3520 F Appliance - All flash: All versions

ThinkAgile MX Edge Appliance - MX1020: All versions

ThinkAgile HX7821 Certified Node: All versions

ThinkAgile HX7820 Appliance: All versions

ThinkAgile HX7531 Certified Node: All versions

ThinkAgile HX7521 Certified Node: All versions

ThinkAgile HX7520 Appliance: All versions

ThinkAgile HX5531 Certified Node: All versions

ThinkAgile HX5521-C Certified Node: All versions

ThinkAgile HX5521 Certified Node: All versions

ThinkAgile HX5520-C Appliance: All versions

ThinkAgile HX5520 Appliance: All versions

ThinkAgile HX3521-G Certified Node: All versions

ThinkAgile HX3520-G Appliance: All versions

ThinkAgile HX3331 Certified Node: All versions

ThinkAgile HX3330 Appliance: All versions

ThinkAgile HX3321 Certified Node: All versions

ThinkAgile HX3320 Appliance: All versions

ThinkAgile HX2331 Certified Node: All versions

ThinkAgile HX2330 Appliance: All versions

ThinkAgile HX2321 Certified Node: All versions

ThinkAgile HX2320-E Appliance: All versions

ThinkAgile HX2320 Appliance: All versions

ThinkAgile HX1521-R Certified Node: All versions

ThinkAgile HX1520-R Appliance: All versions

ThinkAgile HX1331 Certified Node: All versions

ThinkAgile HX1330 Appliance: All versions

ThinkAgile HX1321 Certified Node: All versions

ThinkAgile HX1320 Appliance: All versions

ThinkAgile VX3331 Certified Node: All versions

ThinkAgile HX7530 Appliance: All versions

ThinkAgile HX5530 Appliance: All versions

System x3950 X6: All versions

System x3850 X6: All versions

System x3750 M4: All versions

System x3650 M5: All versions

System x3500 M5: All versions

Flex Compute Node - x880 X6: All versions

Flex Compute Node - x480 X6: All versions

Flex Compute Node - x280 X6: All versions

Flex Compute Node - x240 M5: All versions

NeXtScale Compute Node - nx360 M5: All versions

ThinkSystem ST658 V3: All versions

ThinkSystem ST658 V2: All versions

ThinkSystem ST650 V3: All versions

ThinkSystem ST650 V2: All versions

ThinkSystem ST558: All versions

ThinkSystem ST550: All versions

ThinkSystem SR860 V3: All versions

ThinkSystem SR860 V2: All versions

ThinkSystem SR850 V3: All versions

ThinkSystem SR850 V2: All versions

ThinkSystem SR670 V2: All versions

ThinkSystem SR650 V3: All versions

ThinkSystem SR630 V3: All versions

ThinkSystem SR630 V2: All versions

ThinkSystem SR258: All versions

ThinkSystem SR250: All versions

ThinkSystem SN850: All versions

ThinkSystem SN550 V2: All versions

ThinkSystem SN550: All versions

ThinkSystem SE350: All versions

ThinkSystem SD650-N V2: All versions

ThinkSystem SD650 V2: All versions

ThinkSystem SD630 V2: All versions

ThinkSystem SD530: All versions

ThinkAgile MX1021 on SE350: All versions

ThinkAgile MX Certified Node – Hybrid: All versions

ThinkAgile MX Certified Node – All Flash: All versions

ThinkAgile MX3331-H Hybrid Certified node: All versions

ThinkAgile MX3331-F All-flash Certified node: All versions

ThinkAgile MX3330-H Hybrid Appliance: All versions

ThinkAgile MX3330-F All-flash Appliance: All versions

ThinkAgile HX3721 Certified Node: All versions

ThinkAgile HX3720 Appliance: All versions

ThinkAgile HX2720-E Appliance: All versions

System x3550 M5: All versions

ThinkSystem SR650 V2: All versions

ThinkEdge SE450: All versions

ThinkSystem SR665: All versions

ThinkSystem SR655: All versions

ThinkSystem SR645: All versions

ThinkSystem SR635: All versions

Nvidia-Mellanox ConnectX Networking Adapter/Device VMware Driver: before 43

Nvidia-Mellanox ConnectX Networking Adapter/Device Linux Firmware: before 43

Nvidia-Mellanox ConnectX Networking Adapter/Device Windows Firmware: before 43

Nvidia-Mellanox ConnectX Networking Adapter/Device Windows Driver: before 43

CPE2.3 External links

https://support.lenovo.com/us/en/product_security/LEN-181059


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU99497

Risk: Low

CVSSv4.0: 4.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-0106

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper handling of insufficient privileges, which leads to denial of service, data tampering and limited information disclosure.

Mitigation

Install update from vendor's website.

Vulnerable software versions

ThinkSystem SR950 V3: All versions

ThinkSystem SR950: All versions

ThinkSystem SR860: All versions

ThinkSystem SR850P: All versions

ThinkSystem SR850: All versions

ThinkSystem SR680a V3: All versions

ThinkSystem SR675 V3: All versions

ThinkSystem SR670: All versions

ThinkSystem SR665 V3: All versions

ThinkSystem SR655 V3: All versions

ThinkSystem SR650: All versions

ThinkSystem SR645 V3: All versions

ThinkSystem SR635 V3: All versions

ThinkSystem SR630 V4: All versions

ThinkSystem SR630: All versions

ThinkSystem SD650 DWC Dual Node Tray: All versions

ThinkSystem SD550 V3: All versions

ThinkSystem SD535 V3: All versions

ThinkSystem SD530 V3: All versions

ThinkServer SR860P: All versions

ThinkEdge SE455 V3: All versions

ThinkAgile VX7820: All versions

ThinkAgile VX7575 Integrated System: All versions

ThinkAgile VX7531 Certified Node: All versions

ThinkAgile VX7530 Appliance: All versions

ThinkAgile VX7520 N: All versions

ThinkAgile VX7520: All versions

ThinkAgile VX7375-N Integrated System: All versions

Thinkagile VX7330 Appliance: All versions

ThinkAgile VX7320 N: All versions

ThinkAgile VX650 V2 DPU Certified Node: All versions

ThinkAgile VX5530 Appliance: All versions

ThinkAgile VX5520: All versions

ThinkAgile VX3720: All versions

ThinkAgile VX3575-G Integrated System: All versions

ThinkAgile VX3530-G Appliance: All versions

ThinkAgile VX3520-G: All versions

ThinkAgile VX3376 Certified Node: All versions

ThinkAgile VX3375 Integrated System: All versions

ThinkAgile VX3330 Appliance: All versions

ThinkAgile VX3320: All versions

ThinkAgile VX2375 Integrated System: All versions

ThinkAgile VX2330 Appliance: All versions

ThinkAgile VX2320: All versions

ThinkAgile VX1320: All versions

ThinkAgile VX 4U Certified Node: All versions

ThinkAgile VX 2U4N Certified Node: All versions

ThinkAgile VX 2U Certified Node: All versions

ThinkAgile VX 1U Certified Node: All versions

ThinkAgile VX 1SE Certified Node: All versions

ThinkAgile MX650 V3 Premier System: All versions

ThinkAgile MX650 v3 Integrated System: All versions

ThinkAgile MX650 V3 Certified Node: All versions

ThinkAgile MX630 V3 Integrated System: All versions

ThinkAgile MX630 V3 Certified Node: All versions

ThinkAgile MX3531-F All-flash Certified node: All versions

ThinkAgile MX3531 H Hybrid Certified node: All versions

ThinkAgile MX3530-H Hybrid Appliance: All versions

ThinkAgile MX3530 F All flash Appliance: All versions

ThinkAgile MX3520 H Appliance - Hybrid: All versions

ThinkAgile MX3520 F Appliance - All flash: All versions

ThinkAgile MX Edge Appliance - MX1020: All versions

ThinkAgile HX7821 Certified Node: All versions

ThinkAgile HX7820 Appliance: All versions

ThinkAgile HX7531 Certified Node: All versions

ThinkAgile HX7521 Certified Node: All versions

ThinkAgile HX7520 Appliance: All versions

ThinkAgile HX5531 Certified Node: All versions

ThinkAgile HX5521-C Certified Node: All versions

ThinkAgile HX5521 Certified Node: All versions

ThinkAgile HX5520-C Appliance: All versions

ThinkAgile HX5520 Appliance: All versions

ThinkAgile HX3521-G Certified Node: All versions

ThinkAgile HX3520-G Appliance: All versions

ThinkAgile HX3331 Certified Node: All versions

ThinkAgile HX3330 Appliance: All versions

ThinkAgile HX3321 Certified Node: All versions

ThinkAgile HX3320 Appliance: All versions

ThinkAgile HX2331 Certified Node: All versions

ThinkAgile HX2330 Appliance: All versions

ThinkAgile HX2321 Certified Node: All versions

ThinkAgile HX2320-E Appliance: All versions

ThinkAgile HX2320 Appliance: All versions

ThinkAgile HX1521-R Certified Node: All versions

ThinkAgile HX1520-R Appliance: All versions

ThinkAgile HX1331 Certified Node: All versions

ThinkAgile HX1330 Appliance: All versions

ThinkAgile HX1321 Certified Node: All versions

ThinkAgile HX1320 Appliance: All versions

ThinkAgile VX3331 Certified Node: All versions

ThinkAgile HX7530 Appliance: All versions

ThinkAgile HX5530 Appliance: All versions

System x3950 X6: All versions

System x3850 X6: All versions

System x3750 M4: All versions

System x3650 M5: All versions

System x3500 M5: All versions

Flex Compute Node - x880 X6: All versions

Flex Compute Node - x480 X6: All versions

Flex Compute Node - x280 X6: All versions

Flex Compute Node - x240 M5: All versions

NeXtScale Compute Node - nx360 M5: All versions

ThinkSystem ST658 V3: All versions

ThinkSystem ST658 V2: All versions

ThinkSystem ST650 V3: All versions

ThinkSystem ST650 V2: All versions

ThinkSystem ST558: All versions

ThinkSystem ST550: All versions

ThinkSystem SR860 V3: All versions

ThinkSystem SR860 V2: All versions

ThinkSystem SR850 V3: All versions

ThinkSystem SR850 V2: All versions

ThinkSystem SR670 V2: All versions

ThinkSystem SR650 V3: All versions

ThinkSystem SR630 V3: All versions

ThinkSystem SR630 V2: All versions

ThinkSystem SR258: All versions

ThinkSystem SR250: All versions

ThinkSystem SN850: All versions

ThinkSystem SN550 V2: All versions

ThinkSystem SN550: All versions

ThinkSystem SE350: All versions

ThinkSystem SD650-N V2: All versions

ThinkSystem SD650 V2: All versions

ThinkSystem SD630 V2: All versions

ThinkSystem SD530: All versions

ThinkAgile MX1021 on SE350: All versions

ThinkAgile MX Certified Node – Hybrid: All versions

ThinkAgile MX Certified Node – All Flash: All versions

ThinkAgile MX3331-H Hybrid Certified node: All versions

ThinkAgile MX3331-F All-flash Certified node: All versions

ThinkAgile MX3330-H Hybrid Appliance: All versions

ThinkAgile MX3330-F All-flash Appliance: All versions

ThinkAgile HX3721 Certified Node: All versions

ThinkAgile HX3720 Appliance: All versions

ThinkAgile HX2720-E Appliance: All versions

System x3550 M5: All versions

ThinkSystem SR650 V2: All versions

ThinkEdge SE450: All versions

ThinkSystem SR665: All versions

ThinkSystem SR655: All versions

ThinkSystem SR645: All versions

ThinkSystem SR635: All versions

Nvidia-Mellanox ConnectX Networking Adapter/Device VMware Driver: before 43

Nvidia-Mellanox ConnectX Networking Adapter/Device Linux Firmware: before 43

Nvidia-Mellanox ConnectX Networking Adapter/Device Windows Firmware: before 43

Nvidia-Mellanox ConnectX Networking Adapter/Device Windows Driver: before 43

CPE2.3 External links

https://support.lenovo.com/us/en/product_security/LEN-181059


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###