CVE-2017-3775

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:flex_system_x240_m5_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_x240_m5:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lenovo:flex_system_x280_x6_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_x280_x6:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lenovo:flex_system_x480_x6_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_x480_x6:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:lenovo:flex_system_x880_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_x880:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:lenovo:nextscale_nx360_m5_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:nextscale_nx360_m5:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:lenovo:system_x3250_m6_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3250_m6:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:lenovo:system_x3500_m5_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3500_m5:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:lenovo:system_x3550_m5_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3550_m5:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:lenovo:system_x3650_m5_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3650_m5:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:lenovo:system_x3850_x6_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3850_x6:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:lenovo:system_x3950_x6_bios:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3950_x6:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/solutions/LEN-20241 - Patch, Vendor Advisory () https://support.lenovo.com/us/en/solutions/LEN-20241 - Patch, Vendor Advisory

Information

Published : 2018-05-04 17:29

Updated : 2024-11-21 03:26


NVD link : CVE-2017-3775

Mitre link : CVE-2017-3775

CVE.ORG link : CVE-2017-3775


JSON object : View

Products Affected

lenovo

  • flex_system_x880_bios
  • system_x3850_x6_bios
  • flex_system_x880
  • system_x3650_m5
  • nextscale_nx360_m5
  • flex_system_x280_x6
  • system_x3950_x6_bios
  • system_x3550_m5
  • system_x3500_m5_bios
  • system_x3950_x6
  • flex_system_x280_x6_bios
  • system_x3550_m5_bios
  • system_x3500_m5
  • system_x3850_x6
  • flex_system_x240_m5_bios
  • flex_system_x240_m5
  • system_x3650_m5_bios
  • flex_system_x480_x6_bios
  • flex_system_x480_x6
  • system_x3250_m6_bios
  • nextscale_nx360_m5_bios
  • system_x3250_m6
CWE
CWE-287

Improper Authentication