« Volver al listado

CVE-2024-4550

Estado: AplazadaMedia (6.7)—

A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-4550",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-4550",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-13T21:04:53.687238Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@lenovo.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@lenovo.com",
      "affectedData": [
        {
          "vendor": "Lenovo",
          "product": "P360 Workstation (ThinkStation) BIOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "S0EKT43A"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Lenovo",
          "product": "ST50 (ThinkSystem) BIOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "ITE134A",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Lenovo",
          "product": "ST50 V2 (ThinkSystem) BIOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "TOE112D",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Lenovo",
          "product": "ST58 (ThinkSystem) BIOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "ITE134A",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Lenovo",
          "product": "ST58 V2 (ThinkSystem) BIOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "TOE112D",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:lenovo:thinkstation_p360_workstation_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "lenovo",
          "product": "thinkstation_p360_workstation_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "s0ekt43a",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:lenovo:thinksystem_st50_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "lenovo",
          "product": "thinksystem_st50_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "ite134a",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:lenovo:thinksystem_st50_v2_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "lenovo",
          "product": "thinksystem_st50_v2_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "toe112d",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:lenovo:thinksystem_st58_v2_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "lenovo",
          "product": "thinksystem_st58_v2_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "toe112d",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:lenovo:thinksystem_st58_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "lenovo",
          "product": "thinksystem_st58_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "ite134a",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-13T18:15:05.800",
  "references": [
    {
      "url": "https://support.lenovo.com/us/en/product_security/LEN-165524",
      "source": "psirt@lenovo.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@lenovo.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Se informó de una posible vulnerabilidad de desbordamiento de búfer en algunos productos Lenovo ThinkSystem y ThinkStation que podría permitir que un atacante local con privilegios elevados ejecute código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T08:02:07.210",
  "sourceIdentifier": "psirt@lenovo.com"
}