Junglewise Threat Intelligence

CVE-2016-8226: Lenovo System X BIOS denial of service in UEFI data structure

CVE-2016-8226 · Severity: medium · CVSS 4.9 · Published 2017-01-26

Vendors: Lenovo.

Executive brief

A vulnerability in the BIOS of several Lenovo System X servers could allow an administrator to crash the system. By incorrectly updating a specific internal data structure, the server may become unresponsive or fail to operate. This results in a denial of service, potentially disrupting business operations and requiring manual intervention to restore service.

Technical details

A denial of service vulnerability exists in the UEFI BIOS of Lenovo System X M5, M6, and X6 series servers. The flaw is categorized as a data processing error (CWE-19) occurring during the update of a UEFI data structure. An attacker with administrative privileges can trigger this condition over the network without user interaction. Successful exploitation results in a complete loss of availability for the affected system. Lenovo has released a security advisory (LEN-11306) to address this issue.

Affected products

  • Lenovo System X M5 BIOS
  • Lenovo System X M6 BIOS
  • Lenovo System X X6 BIOS
  • Lenovo Flex System x240 M5 BIOS
  • Lenovo Flex System x280 M6 BIOS
  • Lenovo Flex System x480 X6 BIOS
  • Lenovo Flex System x880 X6 BIOS
  • Lenovo NeXtScale nx360 M5 BIOS
  • Lenovo System x3250 M6 BIOS
  • Lenovo System x3500 M5 BIOS
  • Lenovo System x3550 M5 BIOS
  • Lenovo System x3650 M5 BIOS
  • Lenovo System x3850 X6 BIOS
  • Lenovo System x3950 X6 BIOS

Timeline

  • 2017-01-26: advisory: NVD published date
  • 2017-01-26: disclosed: Initial disclosure date

References