Executive brief
A vulnerability in the BIOS of several Lenovo System X servers could allow an administrator to crash the system. By incorrectly updating a specific internal data structure, the server may become unresponsive or fail to operate. This results in a denial of service, potentially disrupting business operations and requiring manual intervention to restore service.
Technical details
A denial of service vulnerability exists in the UEFI BIOS of Lenovo System X M5, M6, and X6 series servers. The flaw is categorized as a data processing error (CWE-19) occurring during the update of a UEFI data structure. An attacker with administrative privileges can trigger this condition over the network without user interaction. Successful exploitation results in a complete loss of availability for the affected system. Lenovo has released a security advisory (LEN-11306) to address this issue.
Affected products
- Lenovo System X M5 BIOS
- Lenovo System X M6 BIOS
- Lenovo System X X6 BIOS
- Lenovo Flex System x240 M5 BIOS
- Lenovo Flex System x280 M6 BIOS
- Lenovo Flex System x480 X6 BIOS
- Lenovo Flex System x880 X6 BIOS
- Lenovo NeXtScale nx360 M5 BIOS
- Lenovo System x3250 M6 BIOS
- Lenovo System x3500 M5 BIOS
- Lenovo System x3550 M5 BIOS
- Lenovo System x3650 M5 BIOS
- Lenovo System x3850 X6 BIOS
- Lenovo System x3950 X6 BIOS
Timeline
- 2017-01-26: advisory: NVD published date
- 2017-01-26: disclosed: Initial disclosure date