Lenovo notebooks, servers, desktops with BIOS vulnerabilities

Share post

ESET had already discovered dangerous UEFI security gaps in Lenovo notebooks in April. Lenovo itself is now reporting that it recommends installing new firmware for more than 500 models, as there are sometimes highly dangerous security gaps.

Lenovo has to lower the head again and report the presence of many security vulnerabilities in various BIOS versions of their devices. Already had to a few months ago Lenovo to patch the vulnerabilities found by ESET in many UEFI BIOS versions. The currently published list of affected BIOS versions is again quite long. In addition to desktop PCs, notebooks, workstations, storage, and servers, Lenovo lists the associated problems and recommends updates. The list names more than 500 devices!

New BIOS update list for September 2022

🔎 Lenovo names security updates for over 94953 devices in LEN-500 in September (Image: Lenovo).

On its website, Lenovo lists various security recommendations under the following point “Multi-Vendor BIOS Security Vulnerabilities (September 2022)” (LEN-94953). Lenovo cites the following risks for the potential attack: Disclosure of information, escalation of rights, denial of service. The vulnerabilities have a severity of High. The following CVE identifiers are specified: CVE-2021-28216, CVE-2022-40134, CVE-2022-40135, CVE-2022-40136, CVE-2022-40137.

In the very extensive list, Lenovo lists the affected devices individually. It also explains in detail which of the CVEs are affected. Sometimes all vulnerabilities are gathered together, sometimes there are only one or two vulnerabilities. But no matter what the vulnerability is: the updates should be implemented as quickly as possible. If you don't get along with this, you will find a link to an update tool at the beginning of the table.

More at Lenovo.com

 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more

Data encryption: More security on cloud platforms

Online platforms are often the target of cyberattacks, such as Trello recently. 5 tips ensure more effective data encryption in the cloud ➡ Read more