cbcvebase.
CVE-2020-8333
published 2020-09-24

CVE-2020-8333: A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.6th percentile
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
lenovo63_firmware< fckt98afckt98a
lenovobios
lenovoh50-30g_firmware< fckt98afckt98a
lenovom4500_firmware< fckt98afckt98a
lenovom4550_firmware< fckt98afckt98a
lenovoqitian_4500_firmware< fckt98afckt98a
lenovoqitian_b4550_firmware< fckt98afckt98a
lenovoqitian_m4550_firmware< fckt98afckt98a
lenovothinkcentre_e73_firmware< fckt98afckt98a
lenovothinkcentre_e73s_firmware< fckt98afckt98a
lenovothinkcentre_e93_firmware< fbktdeafbktdea
lenovothinkcentre_m4500k_firmware< fckt98afckt98a
lenovothinkcentre_m4500q_firmware< fhkt85afhkt85a
lenovothinkcentre_m4500s_firmware< fckt98afckt98a
lenovothinkcentre_m4500t_firmware< fckt98afckt98a
lenovothinkcentre_m9350z_firmware< fekta2afekta2a
lenovothinkcentre_m93z_firmware< fekta2afekta2a
lenovothinkstation_c30_firmware< a3kt70aa3kt70a
lenovothinkstation_d30_firmware< a3kt70aa3kt70a
lenovothinkstation_e32_firmware< fbktdeafbktdea
lenovothinkstation_p300_firmware< a2kt70aa2kt70a
lenovothinkstation_s30_firmware< a2kt70aa2kt70a
lenovoyangtian_afh81_firmware< fckt98afckt98a
lenovoyangtian_mc_h81_firmware< fckt98afckt98a
lenovoyangtian_mf_h81_pci_firmware< fckt98afckt98a

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.