Medium severity6.4NVD Advisory· Published May 4, 2018· Updated Jun 17, 2026
CVE-2017-3775
CVE-2017-3775
Description
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
Affected products
12- cpe:2.3:o:lenovo:flex_system_x240_m5_bios:*:*:*:*:*:*:*:*Range: <2.61
- cpe:2.3:o:lenovo:flex_system_x280_x6_bios:*:*:*:*:*:*:*:*Range: <4.21
- cpe:2.3:o:lenovo:flex_system_x480_x6_bios:*:*:*:*:*:*:*:*Range: <4.21
cpe:2.3:o:lenovo:system_x3850_x6_bios:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:lenovo:system_x3850_x6_bios:*:*:*:*:*:*:*:*range: <4.3
- cpe:2.3:o:lenovo:system_x3950_x6_bios:*:*:*:*:*:*:*:*range: <4.3
- Lenovo Group Ltd./Some Lenovo Flex System and Lenovo System x productsv5Range: Affected BIOS version varies by product
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/solutions/LEN-20241nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.