Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU93105
Risk: Low
CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-21828
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and gain unauthorized access to the application.
MitigationInstall update from vendor's website.
Vulnerable software versionsThinkSystem SD665 V3: All versions
ThinkSystem SD650-N V3: All versions
ThinkSystem SD650-I V3: All versions
ThinkSystem SD650 V3: All versions
ThinkSystem ST58 V3: All versions
ThinkSystem ST58 V2: All versions
ThinkSystem ST50 V3: All versions
ThinkSystem ST50 V2: All versions
ThinkSystem ST258 V3: All versions
ThinkSystem ST258 V2: All versions
ThinkSystem ST250 V2: All versions
ThinkSystem SR258 V3: All versions
ThinkSystem SR258 V2: All versions
ThinkSystem SR250 V3: All versions
ThinkSystem SR250 V2: All versions
ThinkSystem ST250 V3: All versions
ThinkServer SR668 V2: All versions
ThinkServer SR660 V2: All versions
ThinkAgile MX450 Edge IS: All versions
Thinksmart Hub 500: All versions
ThinkStation PX Workstation: All versions
ThinkStation P620 Workstation: All versions
ThinkEdge SE30: All versions
ThinkSmart Hub Zoom: All versions
ThinkSmart Hub Teams: All versions
ThinkEdge SE10: All versions
ThinkCentre M90n-1: All versions
ThinkPad L14 Gen 2 Type 20X1 20X2: All versions
ThinkBook 15 G5 IRL: All versions
ThinkBook 14 G5 IRL: All versions
ThinkSystem SR950 V3: All versions
ThinkSystem SR950: All versions
ThinkSystem SR860: All versions
ThinkSystem SR850P: All versions
ThinkSystem SR850: All versions
ThinkSystem SR675 V3: All versions
ThinkSystem SR670: All versions
ThinkSystem SR665 V3: All versions
ThinkSystem SR655 V3: All versions
ThinkSystem SR650: All versions
ThinkSystem SR645 V3: All versions
ThinkSystem SR635 V3: All versions
ThinkSystem SR630: All versions
ThinkSystem SD650 DWC Dual Node Tray: All versions
ThinkSystem SD550 V3: All versions
ThinkSystem SD535 V3: All versions
ThinkSystem SD530 V3: All versions
ThinkEdge SE455 V3: All versions
ThinkAgile VX7820: All versions
ThinkAgile VX7575 Integrated System: All versions
ThinkAgile VX7531 Certified Node: All versions
ThinkAgile VX7530 Appliance: All versions
ThinkAgile VX7520 N: All versions
ThinkAgile VX7520: All versions
ThinkAgile VX7375-N Integrated System: All versions
Thinkagile VX7330 Appliance: All versions
ThinkAgile VX7320 N: All versions
ThinkAgile VX650 V2 DPU Certified Node: All versions
ThinkAgile VX5530 Appliance: All versions
ThinkAgile VX5520: All versions
ThinkAgile VX3720: All versions
ThinkAgile VX3575-G Integrated System: All versions
ThinkAgile VX3530-G Appliance: All versions
ThinkAgile VX3520-G: All versions
ThinkAgile VX3376 Certified Node: All versions
ThinkAgile VX3375 Integrated System: All versions
ThinkAgile VX3330 Appliance: All versions
ThinkAgile VX3320: All versions
ThinkAgile VX2375 Integrated System: All versions
ThinkAgile VX2330 Appliance: All versions
ThinkAgile VX2320: All versions
ThinkAgile VX1320: All versions
ThinkAgile VX 4U Certified Node: All versions
ThinkAgile VX 2U4N Certified Node: All versions
ThinkAgile VX 2U Certified Node: All versions
ThinkAgile VX 1U Certified Node: All versions
ThinkAgile VX 1SE Certified Node: All versions
ThinkAgile MX650 v3 Integrated System: All versions
ThinkAgile MX650 V3 Certified Node: All versions
ThinkAgile MX630 V3 Integrated System: All versions
ThinkAgile MX630 V3 Certified Node: All versions
ThinkAgile MX3531-F All-flash Certified node: All versions
ThinkAgile MX3531 H Hybrid Certified node: All versions
ThinkAgile MX3530-H Hybrid Appliance: All versions
ThinkAgile MX3530 F All flash Appliance: All versions
ThinkAgile MX3520 H Appliance - Hybrid: All versions
ThinkAgile MX3520 F Appliance - All flash: All versions
ThinkAgile MX Edge Appliance - MX1020: All versions
ThinkAgile VX3331 Certified Node: All versions
ThinkSystem ST658 V3: All versions
ThinkSystem ST658 V2: All versions
ThinkSystem ST650 V3: All versions
ThinkSystem ST650 V2: All versions
ThinkSystem ST58: All versions
ThinkSystem ST558: All versions
ThinkSystem ST550: All versions
ThinkSystem ST50: All versions
ThinkSystem ST258: All versions
ThinkSystem ST250: All versions
ThinkSystem SR860 V3: All versions
ThinkSystem SR860 V2: All versions
ThinkSystem SR850 V3: All versions
ThinkSystem SR850 V2: All versions
ThinkSystem SR670 V2: All versions
ThinkSystem SR650 V3: All versions
ThinkSystem SR630 V3: All versions
ThinkSystem SR630 V2: All versions
ThinkSystem SR590: All versions
ThinkSystem SR570: All versions
ThinkSystem SR550: All versions
ThinkSystem SR530: All versions
ThinkSystem SR258: All versions
ThinkSystem SR250: All versions
ThinkSystem SR158: All versions
ThinkSystem SR150: All versions
ThinkSystem SN850: All versions
ThinkSystem SN550: All versions
ThinkSystem SE350: All versions
ThinkSystem SD630 V2: All versions
ThinkSystem SD530: All versions
ThinkServer SR590 V2: All versions
ThinkServer SR588 V2: All versions
ThinkServer DN8848 V2: All versions
ThinkAgile MX1021 on SE350: All versions
ThinkAgile MX Certified Node – Hybrid: All versions
ThinkAgile MX Certified Node – All Flash: All versions
ThinkAgile MX3331-H Hybrid Certified node: All versions
ThinkAgile MX3331-F All-flash Certified node: All versions
ThinkAgile MX3330-H Hybrid Appliance: All versions
ThinkAgile MX3330-F All-flash Appliance: All versions
ThinkAgile HX3721 Certified Node: All versions
ThinkAgile HX3720 Appliance: All versions
ThinkAgile HX2720-E Appliance: All versions
ThinkSystem SR650 V2: All versions
ThinkEdge SE450: All versions
ThinkEdge SE360 V2: All versions
ThinkPad L14 20U2: All versions
ThinkPad L14 20U1: All versions
ThinkPad E15 Gen 4 21E7: All versions
ThinkPad E15 Gen 4 21E6: All versions
ThinkPad E14 Gen 5 21JL: All versions
ThinkPad E14 Gen 5 21JK: All versions
ThinkPad E14 Gen 4 21E4: All versions
ThinkPad E14 Gen 4 21E3: All versions
ThinkPad R14 Gen 5 Type 21JM PRC: All versions
ThinkPad E16 Gen 1 21JQ: All versions
ThinkPad E16 Gen 1 21JN: All versions
ThinkStation P7 Intel Workstation: All versions
ThinkStation P5 Workstation: All versions
ThinkStation P920 Workstation: All versions
ThinkStation P720 Workstation: All versions
ThinkStation P520c Workstation: All versions
ThinkStation P520 Workstation: All versions
ThinkStation P360 Workstation: All versions
ThinkStation P3 Ultra Workstation: All versions
ThinkStation P3 Tower Workstation: All versions
ThinkPad L15 Gen 2 Type 20X3 20X4: All versions
ThinkPad L15 20U4: All versions
ThinkPad L15 20U3: All versions
ThinkSmart One & ThinkSmart Controller: Zoom Rooms: All versions
ThinkSmart One & ThinkSmart Controller: Microsoft Teams Rooms: All versions
ThinkSmart One & IP Controller: Zoom Rooms: All versions
ThinkSmart One & IP Controller: Microsoft Teams Rooms: All versions
ThinkSmart Core IP Controller Kit & Bar 180: All versions
ThinkSmart Core Device: Zoom Rooms: All versions
ThinkSmart Core Device: Basic: All versions
ThinkSmart Core Device for Poly: All versions
ThinkSmart Core Device for Logitech: All versions
ThinkSmart Core Controller Kit & Bar 180: All versions
ThinkSmart Core & ThinkSmart Controller Kit: Zoom Rooms: All versions
ThinkSmart Core & ThinkSmart Controller Kit: Microsoft Teams Rooms: All versions
ThinkSmart Core & ThinkSmart Controller Full Room Kit: Zoom Rooms: All versions
ThinkSmart Core & ThinkSmart Controller Full Room Kit: Microsoft Teams Rooms: All versions
ThinkSmart Core & IP Controller Kit: Zoom Rooms: All versions
ThinkSmart Core & IP Controller Kit: Microsoft Teams Rooms/Zoom Rooms: All versions
ThinkSmart Core & IP Controller Kit: Microsoft Teams Rooms: All versions
ThinkSmart Core & IP Controller Full Room Kit: Zoom Rooms: All versions
ThinkSmart Core & IP Controller Full Room Kit: Microsoft Teams Rooms: All versions
ThinkEdge SE50: All versions
ThinkSystem SR665: All versions
ThinkSystem SR655: All versions
ThinkSystem SR645: All versions
ThinkSystem SR635: All versions
Intel X710 Ethernet Firmware for Windows 10 (64-bit), Linux- ThinkStation P620: before 9.3
Intel LAN Card I350-T2/T4 Firmware for Windows 11 and 10 (64-bit) - ThinkStation P620: before 1.3534.0
Intel X710-DA2 Ethernet Converged Network Adapter (SFP+) Adapter image for Windows 10 (64-bit), Windows 7 (64-bit), Linux - ThinkStation P520, P520c, P720, P920: before 9.30
Intel I350-T2/T4 Gigabit Ethernet Adapter image for Windows 10 (Version 20H2) , RHEL 8.3 - ThinkStation P520, P520c, P720, P920: before 1.3534.0
Intel I210-T1 Single Port Gigabit Ethernet Adapter (Beaver Lake) Adapter image for Windows 10 64-bit (Version 2004), Windows 7 (64-bit), Red Hat 8.1 - ThinkStation P520, P520c, P720, P920: before 3.30
Intel I210-T1 Single Port Gigabit Ethernet Adapter (Beaver Lake) Adapter image for Windows 10 (Version 20H2) - ThinkStation P520, P520c, P720, P920: before 3.30
Intel Ethernet Converged Network Adapter X550-T2 adapter image for Windows 10 (Version 20H2), RHEL 8.3 - ThinkStation P520, P520c, P720, P920: before 3.60
Intel LAN I210-T1, I350-T2, I350-T4, X550-T2 Firmware for Windows 10 and 11 - ThinkStation PX, P5, P7: before 1.3534.0
Intel Lan X550-T2 Firmware for Windows 10 (64-bit), 11, Linux - ThinkStation P3 Ultra, P620: before NVM3.60
Intel I210-T1 Firmware for Windows 10 and 11 - ThinkStation P3, P360: before 1.3534.0
Intel PRO1000 LAN Adapter Software for Windows 11 (Version 21H2 or later), 10 (Version 1903 or later) - ThinkPad L14 Gen 2 (Type 20X1, 20X2), L15 Gen 2 (Type 20X3, 20X4): before 12.19.2.56
Intel PRO/1000 LAN Adapter Software for Windows 11 (Version 21H2 or later), 10 (Version 1809 or later) - ThinkPad L14 Gen 1 (Type 20U1, 20U2), L15 Gen 1 (Type 20U3, 20U4): before 12.19.2.56
Intel Ethernet Driver for Windows 11 (Version 22H2 or later), 10 64-bit (Version 22H2 or later) - ThinkPad E14 Gen 5 (Type 21JK, 21JL), E16 Gen 1 (Type 21JN, 21JQ): before 12.19.2.56
Intel PRO1000 LAN Adapter Software for Windows 11 (Version 21H2 or later), 10 (Version 21H2 or later) - ThinkPad E14 Gen 4, E15 Gen 4: before 12.19.2.56
Intel Lan Driver for Windows 11 IoT 64-bit (version 22H2) - ThinkSmart One ZOOM: before 12.19.2.56
Intel Lan Driver for Windows IoT 10 (64-bit) (version 21H2, 22H2) - ThinkSmart One Series: before 12.19.2.56
Intel Lan Driver for Windows 11 IoT 64-bit (version 22H2) - ThinkSmart One MTR: before 12.19.2.56
Intel Ethernet Driver for Windows IoT 10 (64-bit) - ThinkSmart Hub Zoom: before 12.19.2.56
Intel Lan Driver for Windows 10 IoT (64-bit), Windows 11 IoT (64-bit)- ThinkSmart Hub Teams, ThinkSmart Hub Zoom: before 12.19.2.56
Intel Gigabit Ethernet Driver for Windows IoT 10 (64-bit) - ThinkSmart Hub Teams: before 12.19.2.56
Intel LAN Driver for Windows IoT 10 (64-bit) - ThinkSmart Core: before 12.19.2.56
Intel Gigabit Ethernet Driver for Windows IoT 10 (64-bit) - ThinkSmart Core: before 12.19.2.56
Intel On-board Lan driver for Windows IoT 10 (64-bit) - ThinkEdge SE50: before 14.0.2.0
Intel(R) Ethernet Controller Driver for Windows IoT 10 64-bit (version 1809) - ThinkEdge SE30: before 1.1.4.42
Intel(R) Ethernet Controller Driver for Windows 10 64-bit (version 21h1) - ThinkEdge SE30: before 1.1.4.42
Intel I225 LAN driver for Windows IoT 10 64-bit (version 21H2) , Windows 10 (64-bit), Windows 11 (64-bit) - ThinkEdge SE30: before 1.1.4.42
Intel Ethernet Driver for Windows 10 IoT (64-bit) (For 21H2) - ThinkEdge SE10: before 1.1.4.42
Intel Ethernet Driver for Windows 10 IoT (64-bit) (For 2019) - ThinkEdge SE10: before 1.1.4.42
Intel LAN Driver for Windows 10 IOT 64-bit - ThinkCentre M90n-1: before 12.19.2.56
Intel LAN Driver for Windows 10 IoT (64-bit), Windows IoT 11 (64-bit) - ThinkSmart Series: before 12.19.2.56
Intel LAN Driver for Windows 10 64-bit - ThinkCentre M90n-1: before 12.19.2.56
Intel LAN Driver for Windows 11 (64-bit) - ThinkBook 14 G5 IRL, ThinkBook 15 G5 IRL: before 12.19.2.56
Intel LAN Driver for Windows 10 (64-bit) - ThinkBook 14 G5 IRL, ThinkBook 15 G5 IRL: before 12.19.2.56
Intel v26.0 Network FW Update Release for Windows for SD530 X722 (For Windows): before 9.50-6.50-1.3616.0
Intel Networking Adapter/Device VMware Driver: before NET-20240521
Intel Networking Adapter/Device SLES 15 Driver: before 29.1
Intel Networking Adapter/Device RHEL 9 Driver: before 29.1
Intel Networking Adapter/Device RHEL 8 Driver: before 29.1
Intel Networking Adapter/Device Windows Driver: before 29.1
Intel v25.5 X722 SD530 FW Update Release for Windows (For Windows): before 9.50-6.50-1.3616.0
Intel v25.5 X722 SD530 FW Update Release for Linux (For Linux): before 9.50-6.50-1.3616.0
Intel Networking Adapter/Device Linux Firmware: before 3.39-1.3602.0
CPE2.3https://support.lenovo.com/us/en/product_security/LEN-156780
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.