Database/Firmware, BMC & network fabric
Lenovo ThinkSystem / ThinkStation (firmware buffer overflow): A local attacker with elevated privileges executes
CVSS 6.7CVE-2024-4550Firmware, BMC & network fabriccurated
Impact
A local attacker with elevated privileges executes arbitrary code via a firmware buffer overflow on ThinkSystem servers.
Who can reach it
Local elevated-privilege access to the server.
What to do
Apply the Lenovo firmware update per LEN-165524. Firmware flash requiring a reboot - batch with other node firmware work.
References
Related entries
- GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted imageCVE-2024-45774 · GRUB2 (JPEG parser)Medium
- GRUB2 (commands/extcmd): A failed allocation goes unchecked, so GRUB proceeds on a NULL pointer and its stateCVE-2024-45775 · GRUB2 (commands/extcmd)Medium
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionCVE-2024-45778 · GRUB2 (BFS filesystem parser)Medium
- GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of boundsCVE-2024-45780 · GRUB2 (tar filesystem parser)Medium
- GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFSCVE-2024-45781 · GRUB2 (UFS filesystem parser)Medium
- Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620CVE-2024-47976 · Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.