CVE-2017-3775: Lenovo Flex System x240 m5 BIOS
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
Affected products
- Lenovo Flex System x240 m5 BIOS: before 2.61 (fixed in 2.61)
- Lenovo Flex System x280 x6 BIOS: before 4.21 (fixed in 4.21)
- Lenovo Flex System x480 x6 BIOS: before 4.21 (fixed in 4.21)
- Lenovo Flex System x880 BIOS: before 4.21 (fixed in 4.21)
- Lenovo Nextscale NX360 m5 BIOS: before 2.61 (fixed in 2.61)
- Lenovo System x3250 m6 BIOS: before 2.23 (fixed in 2.23)
- Lenovo System x3500 m5 BIOS: before 2.61 (fixed in 2.61)
- Lenovo System x3550 m5 BIOS: before 2.61 (fixed in 2.61)
- Lenovo System x3650 m5 BIOS: before 2.61 (fixed in 2.61)
- Lenovo System x3850 x6 BIOS: before 4.3 (fixed in 4.3)
- Lenovo System x3950 x6 BIOS: before 4.3 (fixed in 4.3)
Published 2018-05-04. Last modified 2026-06-17.