CVE-2017-3771: Lenovo Aio e95 Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.

Affected products

  • Lenovo Aio e95 Firmware: before m16kt40a (fixed in m16kt40a)
  • Lenovo Thinkcentre m710s Firmware: before m16kt40a (fixed in m16kt40a)
  • Lenovo Thinkcentre m710t Firmware: before m16kt40a (fixed in m16kt40a)

Published 2017-10-26. Last modified 2026-06-17.