7.2
CVSSv2

CVE-2021-4210

Published: 22/04/2022 Updated: 09/08/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo stadia_ggp-120_firmware -

lenovo thinkedge_se30_firmware -

lenovo v540-24iwl_firmware -

lenovo thinkstation_p520_firmware -

lenovo thinkstation_p310_firmware -

lenovo v50t-13imb_firmware -

lenovo thinkstation_p520c_firmware -

lenovo a540-27icb_firmware -

lenovo a540-24icb_firmware -

lenovo ideacentre_g5-14imb05_firmware -

lenovo v410z_firmware -

lenovo thinkcentre_m910z_firmware -

lenovo thinkcentre_m70a_firmware -

lenovo thinkcentre_m75n_firmware -

lenovo thinkcentre_x1_firmware -

lenovo thinkcentre_m900_firmware -

lenovo thinkcentre_m810z_firmware -

lenovo thinkcentre_m90a_gen2_firmware -

lenovo thinkcentre_m820z_firmware -

lenovo ideacentre_aio_3-27itl6_firmware -

lenovo ideacentre_aio_3-24itl6_firmware -

lenovo thinkcentre_m900x_firmware -

lenovo thinkcentre_m800_firmware -

lenovo ideacentre_aio_3-24iil5_firmware -

lenovo thinkcentre_m700_firmware -

lenovo thinkcentre_m700_tiny_firmware -

lenovo ideacentre_aio_3-24ada6_firmware -

lenovo ideacentre_aio_3-22itl6_firmware -

lenovo ideacentre_aio_3-22iil5_firmware -

lenovo ideacentre_aio_3-22ada6_firmware -

lenovo ideacentre_5-14imb05_firmware -

lenovo ideacentre_c5-14imb05_firmware -