Lenovo Alerts
3032Warning Date
Severity Level
Warning Number
Target Sector
15 December, 2021
● Critical
2021-4068
All
Description:
Lenovo has released security alertsto address multiple vulnerabilities in the following products:
- Apache Log4j
- Lenovo DSS-G
- Lenovo XClarity Administrator (LXCA)
- Lenovo XClarity Energy Manager (LXEM)
- Lenovo XClarity Integrator (LXCI) for VMware vCenter
- NetApp ONTAP Tools for VMware
- ThinkAgile HX
- Nutanix Components
- VMware Components
- ThinkAgile VX
- VMware Components
- Lenovo XClarity Controller (XCC) Firmware
- ThinkAgile
- ThinkStation
- ThinkSystem
- FPC2 and SMM Firmware
- System x
- ThinkAgile
- ThinkSystem
- AMD Secure Encrypted Virtualization (SEV)
- ThinkAgile
- ThinkSystem
- Lenovo Vantage Component
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Authentication bypass
- Escalation of privilege
- Unauthorized disclosure of information
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review Lenovo security advisory and apply the necessary updates if applicable: