Your review has been sent successfully

Lenovo Alerts

3032
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

15 December, 2021

● Critical

2021-4068

All

Description:

Lenovo has released security alertsto address multiple vulnerabilities in the following products:

  • Apache Log4j
    • Lenovo DSS-G
    • Lenovo XClarity Administrator (LXCA)
    • Lenovo XClarity Energy Manager (LXEM)
    • Lenovo XClarity Integrator (LXCI) for VMware vCenter
    • NetApp ONTAP Tools for VMware
    • ThinkAgile HX
      • Nutanix Components
      • VMware Components
    • ThinkAgile VX
      • VMware Components
  • Lenovo XClarity Controller (XCC) Firmware
    • ThinkAgile
    • ThinkStation
    • ThinkSystem
  • FPC2 and SMM Firmware
    • System x
    • ThinkAgile
    • ThinkSystem
  • AMD Secure Encrypted Virtualization (SEV)
    • ThinkAgile
    • ThinkSystem
  • Lenovo Vantage Component

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Authentication bypass
  • Escalation of privilege
  • Unauthorized disclosure of information
  • Remote code execution

Best practice and Recommendations:

The CERT team encourages users to review Lenovo security advisory and apply the necessary updates if applicable:

Last updated at 15 December, 2021

Rate the content

rate-icon
up icon