Home
MEDIUM: 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NMEDIUM: 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
Any version before 4.40
affected
Default status
unaffected
Any version before 4.20
affected
Description
An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.
Problem types
Product status
Any version before 4.40
Any version before 4.20
Credits
Lenovo thanks Eason for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-193044