CVE-2024-4550: Lenovo p360 Workstation Thinkstation BIOS

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.

Affected products

  • Lenovo p360 Workstation Thinkstation BIOS: up to and including S0EKT43A
  • Lenovo ST50 Thinksystem BIOS
  • Lenovo ST50 v2 Thinksystem BIOS
  • Lenovo ST58 Thinksystem BIOS
  • Lenovo ST58 v2 Thinksystem BIOS
  • Lenovo Thinkstation p360 Workstation Firmware: before s0ekt43a (fixed in s0ekt43a)
  • Lenovo Thinksystem ST50 Firmware
  • Lenovo Thinksystem ST50 v2 Firmware
  • Lenovo Thinksystem ST58 Firmware
  • Lenovo Thinksystem ST58 v2 Firmware

Published 2024-09-13. Last modified 2026-06-17.