CVE-2017-3775: Lenovo Flex System x240 m5 BIOS

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

Affected products

  • Lenovo Flex System x240 m5 BIOS: before 2.61 (fixed in 2.61)
  • Lenovo Flex System x280 x6 BIOS: before 4.21 (fixed in 4.21)
  • Lenovo Flex System x480 x6 BIOS: before 4.21 (fixed in 4.21)
  • Lenovo Flex System x880 BIOS: before 4.21 (fixed in 4.21)
  • Lenovo Nextscale NX360 m5 BIOS: before 2.61 (fixed in 2.61)
  • Lenovo System x3250 m6 BIOS: before 2.23 (fixed in 2.23)
  • Lenovo System x3500 m5 BIOS: before 2.61 (fixed in 2.61)
  • Lenovo System x3550 m5 BIOS: before 2.61 (fixed in 2.61)
  • Lenovo System x3650 m5 BIOS: before 2.61 (fixed in 2.61)
  • Lenovo System x3850 x6 BIOS: before 4.3 (fixed in 4.3)
  • Lenovo System x3950 x6 BIOS: before 4.3 (fixed in 4.3)

Published 2018-05-04. Last modified 2026-06-17.