CVE-2024-45105: Lenovo HX1331 Certified Node Thinkagile BIOS
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
Affected products
- Lenovo HX1331 Certified Node Thinkagile BIOS
- Lenovo HX2330 Appliance Thinkagile BIOS
- Lenovo HX2331 Certified Node Thinkagile BIOS
- Lenovo HX3330 Appliance Thinkagile BIOS
- Lenovo HX3331 Certified Node Thinkagile BIOS
- Lenovo HX3331 Node SAP Hana Thinkagile BIOS
- Lenovo HX3375 Appliance Thinkagile BIOS: before D8E138D (fixed in D8E138D)
- Lenovo HX3376 Certified Node Thinkagile BIOS: before D8E138D (fixed in D8E138D)
- Lenovo HX5530 Appliance Thinkagile BIOS
- Lenovo HX5531 Certified Node Thinkagile BIOS
- Lenovo HX630 v3 Certified Node Thinkagile BIOS
- Lenovo HX630 v3 Integrated System Thinkagile BIOS
- Lenovo HX645 v3 Certified Node Thinkagile BIOS
- Lenovo HX645 v3 Integrated System Thinkagile BIOS
- Lenovo HX650 v3 Certified Node Thinkagile BIOS
- Lenovo HX650 v3 Integrated System Thinkagile BIOS
- Lenovo HX665 v3 Certified Node Thinkagile BIOS
- Lenovo HX665 v3 Integrated System Thinkagile BIOS
- Lenovo HX665 v3 Storage Certified Node Thinkagile BIOS
- Lenovo HX665 v3 Storage Integrated Node Thinkagile BIOS
- Lenovo HX7530 Appl For SAP Hana Thinkagile BIOS
- Lenovo HX7531 Certified Node Thinkagile BIOS
- Lenovo HX7531 Node SAP Hana Thinkagile BIOS
- Lenovo MX3330-F All-Flash Appliance Thinkagile BIOS
- Lenovo MX3330-H Hybrid Appliance Thinkagile BIOS
- and 90 more
Published 2024-09-13. Last modified 2026-06-17.