System Management Mode (SMM) BIOS Vulnerability
System Management Mode (SMM) BIOS Vulnerability
System Management Mode (SMM) BIOS Vulnerability
Lenovo Security Advisory: LEN-8324
Potential Impact: Execution of code in SMM by an attacker with local administrative access
Severity: High
Scope of Impact: Industry-wide
Update as of 7/28/2016: Refer to "Revision History" for all new updates.
Update as of 7/19/2016: Updated the "Product Impact" section below of this advisory to say ThinkStations C30, D30 and S30 are not affected. Also the "Original Advisory Text" has been updated with additional information regarding the authorship and purpose of the compromised code. The original advisory text posted on 6/30/16 can be found here.
Update as of 7/11/2016: The "Mitigation" section below of this advisory has been updated.
Update as of 7/7/2016: The "Product Impact" section below of this advisory has been updated.
Summary:
Lenovo’s Product Security Incident Response Team (PSIRT) is fully aware of the uncoordinated disclosure by an independent researcher of a BIOS vulnerability located in the System Management Mode (SMM) code that impacts certain Lenovo as well as other manufacturer’s PC devices. Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information.
Based on the independent researcher’s publicly available proof of concept, physical access is required to exploit a vulnerable device. Successful exploitation of this vulnerability can circumvent security controls on a user’s computer. However, uses of this vulnerability may be expanded to open other exploit methods as individuals or groups with malicious intent leverage it with other existing exploit tools or develop new ones.
Upon further investigation, it was determined that the code was created by Intel with the legitimate original purpose to provide software developers a way to support registering and loading System Management Mode (SMM) drivers for use by the BIOS software. More specifically, the code provided a protocol database and other services for Framework/EDK I-based SMM drivers. It also allowed boot service drivers (specifically dual-mode DXE SMM drivers) to also be reloaded into SMM, thereby allowing one piece of code to serve multiple purposes. This specific implementation was not carried forward in the later revision to EDK I known as EDK II. Instead, EDK II uses a different approach intended to address non-security related functional issues with the original implementation.
The package of code with the SMM vulnerability was provided to Lenovo by at least one of our Independent BIOS Vendors (IBVs) and was developed on top of a common code base provided to the IBV by Intel. Independent BIOS vendors (IBVs) are software development firms that specialize in developing the customized BIOS firmware that is loaded into the PCs of original equipment manufacturers, including Lenovo. Following industry standard practice, IBVs start with the common code bae created by chip vendors, such as Intel or AMD, and add additional layers of code that are specifically designed to work with a particular computer. Lenovo currently works with the industry’s three largest IBVs.
Lenovo is committed to the security of its products and is working with its IBVs and Intel to develop a fix that eliminates this vulnerability as rapidly as possible. Additional information regarding the fix will be posted as soon as it is available on this security advisory page: https://support.lenovo.com/us/en/solutions/LEN-8324
Mitigation (steps you can take to protect yourself):
Security-conscious users should consider the following suggested mitigation steps to protect themselves to the fullest extent possible with the understanding that they DO NOT fix or fully protect against an exploit of this vulnerability:
- Enable Secure Boot on your system
- Disable the boot to UEFI shell
- Disable boot from any source but the primary internal hard drive
- Set a BIOS setup password, so Secure Boot cannot be disabled and the boot to the UEFI shell cannot be re-enabled
- Operate as an unprivileged (non-administrator) user when using Windows
- Run only trusted code from known sources
Users are highly encouraged to follow this advisory page for more information on timing and availability on a fix: https://support.lenovo.com/us/en/solutions/LEN-8324
Please click for more info.
Acknowledgements:
None
References:
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00056&languageid=en-fr
Revision History:
Revision | Date | Description |
32 | 11/29/2016 | Added new releases for ThinkPad - Final |
31 | 11/14/2016 | Added new releases for ThinkPad |
30 | 11/1/2016 | Added new releases for ThinkPad |
29 | 10/25/2016 | Added new releases for ThinkPad and fixed broken links for System x Lenovo |
28 | 10/20/2016 | Added new releases for System x Lenovo and System x IBM |
27 | 10/13/2016 | Added new releases for ThinkPad and ThinkServer; Updated release dates for ThinkPad, System x Lenovo and System x IBM |
26 | 10/2/2016 | Added new releases for ThinkPad; Updated release dates for ThinkPad, System x Lenovo and System x IBM |
25 | 9/28/2016 | Added new releases and updated fix availability dates for ThinkPad |
24 | 9/20/2016 | Added releases for ThinkPad, ThinkServer and updated fix availability for System x (Lenovo and IBM) |
23 | 9/14/2016 | Added releases for ThinkPad. |
22 | 9/12/2016 | Added releases for ThinkPad. |
21 | 9/8/2016 | Update ThinkPad product list; Update System x target availability date |
20 | 9/6/2016 | Added releases for IdeaPad and ThinkPad. |
19 | 8/31/2016 | Added releases for IdeaPad. |
18 | 8/26/2016 | Updated fix targets and new fixes for IdeaPad and ThinkPad; Removed links from ThinkPad for T450, X240, X250 and X1 Carbon (20BS) due to issues reported with the update. New targets are pending. |
17 | 8/16/2016 | Added reference link to Intel advisory; Updated fix targets for ThinkPad; Separated System x IBM legacy models from Lenovo models; Update Desktop & Desktop All-in-One impact |
16 | 8/3/2016 | Add fixes for ThinkPad |
15 | 8/2/2016 | Added additional mitigation option; Updated fix release for IdeaPad and ThinkPad |
14 | 7/29/2016 | Updated ThinkPad status |
13 | 7/28/2016 | Updated IdeaPad, System x and ThinkPad status; Changed advisory formatting |
12 | 7/19/2016 | Updated "Original Advisory Text" with additional information regarding the authorship and purpose of the compromised code |
11 | 7/19/2016 | Updated ThinkStation product impact section to show ThinkStations C30, D30 and S30 are not affected |
10 | 7/14/2016 | Added Desktop All-in-One; Updated status Fix targets |
9 | 7/13/2016 | Updated ThinkStation product impact section |
8 | 7/12/2016 | Formatting changes; Provide clarification that information about updates will be made available on this web page. |
7 | 7/11/2016 | Added System x product impact status |
6 | 7/11/2016 | Updated advisory with Mitigations; Added ThinkStation product impact status |
5 | 7/9/2016 | Added estimated fix availability dates for ThinkPad |
4 | 7/8/2016 | Added estimated fix availability dates for ThinkPad |
3 | 7/8/2016 | Added Desktop product list, additional unaffected ThinkPad models and updated Storage products |
2 | 7/7/2016 | Added known Product Impact |
1 | 6/30/2016 | Initial Statement |
For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on as “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.
Product Impact:
Product | Status |
Erazer X700 Desktop | Not Affected |
IdeaCentre 200 | Not Affected |
IdeaCentre 300-20IBR | Not Affected |
IdeaCentre 300-20ISH | Not Affected |
IdeaCentre 300S-11IBR | Not Affected |
IdeaCentre 300S-11ISH | Not Affected |
IdeaCentre 510S-08ISH | Not Affected |
IdeaCentre 700 | Not Affected |
IdeaCentre Stick | Not Affected |
Lenovo 63 | Not Affected |
Lenovo B2200 | Not Affected |
Lenovo B3300 | Not Affected |
Lenovo B5900 | Not Affected |
Lenovo D5005 | Not Affected |
Lenovo D5055 | Not Affected |
Lenovo E50-00 Deskop | Not Affected |
Lenovo E50-05 | Not Affected |
Lenovo G5010 | Not Affected |
Lenovo H3000 | Not Affected |
Lenovo H30-00 Desktop | Not Affected |
Lenovo H3005 | Not Affected |
Lenovo H30-05 Desktop | Not Affected |
Lenovo H3050 | Not Affected |
Lenovo H30-50 Desktop | Not Affected |
Lenovo H50-00 Desktop | Not Affected |
Lenovo H5005 | Not Affected |
Lenovo H50-05 Desktop | Not Affected |
Lenovo H50-30g Desktop | Not Affected |
Lenovo H5050 | Not Affected |
Lenovo H50-50 Desktop | Not Affected |
Lenovo M2200 | Not Affected |
Lenovo M3300 | Not Affected |
Lenovo M4350 Desktop | Not Affected |
Lenovo M4360 ID | Not Affected |
Lenovo M4500 | Not Affected |
Lenovo M4500 ID | Not Affected |
Lenovo M4550 ID | Not Affected |
Lenovo M5900 | Not Affected |
Lenovo M5900n - China only | Not Affected |
Lenovo S200 | Not Affected |
Lenovo S500 | Not Affected |
QITIAN 4500 | Not Affected |
QITIAN 4500-C | Not Affected |
QITIAN B2200 | Not Affected |
QITIAN B2300 | Not Affected |
QITIAN B3300 | Not Affected |
QITIAN B4550 | Not Affected |
QITIAN B4650 | Not Affected |
QITIAN B5900 | Not Affected |
QITIAN M2200 | Not Affected |
QITIAN M2300 | Not Affected |
QITIAN M3300 | Not Affected |
QITIAN M4550 | Not Affected |
QITIAN M4600 | Not Affected |
QITIAN M4650 | Not Affected |
QITIAN M5900 | Not Affected |
ThinkCentre Chromebox | Not Affected |
ThinkCentre E73 (SFF) | Not Affected |
ThinkCentre E73 (TWR) | Not Affected |
ThinkCentre E73s | Not Affected |
ThinkCentre E74 | Not Affected |
ThinkCentre E74s | Not Affected |
ThinkCentre E79 | Not Affected |
ThinkCentre E93 (SFF) | Not Affected |
ThinkCentre E93 (TWR) | Not Affected |
ThinkCentre Edge 72 | Not Affected |
ThinkCentre M3500q | Not Affected |
ThinkCentre M4350t/s | Not Affected |
ThinkCentre M4500k | Not Affected |
ThinkCentre M4500q | Not Affected |
ThinkCentre M4500t/s | Not Affected |
ThinkCentre M4600t/s | Not Affected |
ThinkCentre M53 (Tiny) | Not Affected |
ThinkCentre M600 | Not Affected |
ThinkCentre M6500t/s | Not Affected |
ThinkCentre M6600 | Not Affected |
ThinkCentre M6600q | Not Affected |
ThinkCentre M6600t/s | Not Affected |
ThinkCentre M700 | Not Affected |
ThinkCentre M72e (Ivy) | Not Affected |
ThinkCentre M72e (PCI) | Not Affected |
ThinkCentre M72e (Tiny) | Not Affected |
ThinkCentre M73 (SFF) | Not Affected |
ThinkCentre M73 (TWR) | Not Affected |
ThinkCentre M73 Tiny | Not Affected |
ThinkCentre M73p | Not Affected |
ThinkCentre M78 (type 10BN, 10BQ, 10BR, 10BS, 10BT, 10BU) | Not Affected |
ThinkCentre M79 (SFF) | Not Affected |
ThinkCentre M79 (TWR) | Not Affected |
ThinkCentre M800 | Not Affected |
ThinkCentre M83 (SFF) | Not Affected |
ThinkCentre M83 (Tiny) | Not Affected |
ThinkCentre M83 (TWR) | Not Affected |
ThinkCentre M8500t/s | Not Affected |
ThinkCentre M8600t/s | Not Affected |
ThinkCentre M900 | Not Affected |
ThinkCentre M92 | Not Affected |
ThinkCentre M92P | Not Affected |
ThinkCentre M93 | Not Affected |
ThinkCentre M93P (SFF) | Not Affected |
ThinkCentre M93P (TWR) | Not Affected |
ThinkCentre M93P Tiny | Not Affected |
YANGTIAN AfH110 | Not Affected |
YANGTIAN AfH81 | Not Affected |
YANGTIAN AfQ150 | Not Affected |
YANGTIAN Mc Carrizo-L | Not Affected |
YANGTIAN Mc Godavari | Not Affected |
YANGTIAN Mc H110 | Not Affected |
YANGTIAN Mc H110 PCI | Not Affected |
YANGTIAN Mc H81 | Not Affected |
YANGTIAN Me/We H110 | Not Affected |
YANGTIAN Mf/Wf H110 PCI | Not Affected |
YANGTIAN Mf/Wf H81 PCI | Not Affected |
YANGTIAN Ms/Ws H81 | Not Affected |
YANGTIAN Tc/Wc H110 PCI | Not Affected |
YANGTIAN TC/WCc H81 PCI | Not Affected |
Product | Status |
Horizon 2 27 Table PC | Not Affected |
Horizon2e Table PC | Not Affected |
IdeaCentre 510S-23ISU | Not Affected |
Lenovo A540 All In One (Broadwell) | Not Affected |
Lenovo A740 All-In-One - BDW | Not Affected |
Lenovo A9050 | Not Affected |
Lenovo B4030 | Not Affected |
Lenovo B40-30 All-In-One | Not Affected |
Lenovo B40-30 Touch All-In-One | Not Affected |
Lenovo B4040 | Not Affected |
Lenovo B5030 | Not Affected |
Lenovo B50-30 All-In-One | Not Affected |
Lenovo B50-30 Touch All-In-One | Not Affected |
Lenovo B5035 | Not Affected |
Lenovo B5040 | Not Affected |
Lenovo C2005 | Not Affected |
Lenovo C20-05 All-In-One | Not Affected |
Lenovo C2030 | Not Affected |
Lenovo C20-30 All-In-One | Not Affected |
Lenovo C260 All--In-One | Not Affected |
Lenovo C260 Touch All-In-One | Not Affected |
Lenovo C360 All-In-One | Not Affected |
Lenovo C4005 | Not Affected |
Lenovo C40-05 All-In-One | Not Affected |
Lenovo C4030 | Not Affected |
Lenovo C40-30 All-In-One | Not Affected |
Lenovo C460 All-In-One | Not Affected |
Lenovo C50-30 All-In-One | Not Affected |
Lenovo C5030-non-Touch | Not Affected |
Lenovo C560 All-In-One | Not Affected |
Lenovo S20-00 | Not Affected |
Lenovo S200z | Not Affected |
Lenovo S4005- China | Not Affected |
Lenovo S400z | Not Affected |
Lenovo S4030 | Not Affected |
Lenovo S40-40 All-In-One | Not Affected |
Lenovo S40-40 White Touch | Not Affected |
Lenovo S405z | Not Affected |
Lenovo S500z | Not Affected |
Lenovo S50-30 | Not Affected |
QITIAN A3300 | Not Affected |
QITIAN A7300 | Not Affected |
QITIAN A8150 | Not Affected |
QITIAN A9050 | Not Affected |
ThinkCenter M700z | Not Affected |
ThinkCenter M800z | Not Affected |
ThinkCentre E63z (AIO) (type 10D4, 10D5, 10D6, 10D7, 10EJ, 10EK) | Not Affected |
ThinkCentre E63z (AIO) (type 10E0, 10E1, 10E2, 10E3, 10EL, 10EM) | Not Affected |
ThinkCentre E73Z (AIO) | Not Affected |
ThinkCentre E74z | Not Affected |
ThinkCentre E93Z (AIO) | Not Affected |
ThinkCentre E93z FO | Not Affected |
ThinkCentre Edge 62z | Not Affected |
ThinkCentre Edge 63z | Not Affected |
ThinkCentre Edge 72z | Not Affected |
ThinkCentre Edge 92z | Not Affected |
ThinkCentre M62Z | Not Affected |
ThinkCentre M700z | Not Affected |
ThinkCentre M7200z | Not Affected |
ThinkCentre M7250z | Not Affected |
ThinkCentre M72z | Not Affected |
ThinkCentre M7300z | Not Affected |
ThinkCentre M73Z (AIO) | Not Affected |
ThinkCentre M800z | Not Affected |
ThinkCentre M8200z | Not Affected |
ThinkCentre M8250z | Not Affected |
ThinkCentre M8300z | Not Affected |
ThinkCentre M8350z | Not Affected |
ThinkCentre M83Z (AIO) | Not Affected |
ThinkCentre M900Z | Not Affected |
ThinkCentre M92Z | Not Affected |
ThinkCentre M9350z | Not Affected |
ThinkCentre M93Z (AIO) | Not Affected |
ThinkCentre M9500z | Not Affected |
ThinkCentre M9550z | Not Affected |
ThinkCentre X1 AIO | Not Affected |
YANGTIAN S2010 | Not Affected |
YANGTIAN S3040 | Not Affected |
YANGTIAN S4030 | Not Affected |
YANGTIAN S4040 | Not Affected |
YANGTIAN S4105 | Not Affected |
YANGTIAN S4130 | Not Affected |
YANGTIAN S4150 | Not Affected |
YANGTIAN s5130 | Not Affected |
YANGTIAN S800 | Not Affected |
Yoga Home 500 | Not Affected |
Product | Status | Estimated Availability of BIOS Update | Minimum BIOS Version Required to Fix | Link to Update | Last Updated |
110-15ACL | Affected | Complete | 1QCN31WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/100-series/110-15ACL/downloads/DS112718 | 8/26/2016 |
110-17ACL | Affected | Complete | 1QCN31WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/100-series/110-17acl/downloads/DS112718 | 8/26/2016 |
500S-14ISK | Not Affected | - | |||
500S-15ISK | Not Affected | - | |||
700-15ISK | Not Affected | - | |||
700-17ISK | Not Affected | - | |||
700S-14ISK | Not Affected | - | |||
710S-13ISK | Not Affected | - | |||
B40-80 | Not Affected | - | |||
B41-30 | Not Affected | - | |||
B41-35 | Not Affected | - | |||
B41-80 | Not Affected | - | |||
B50-80 | Not Affected | - | |||
B51-30 | Not Affected | - | |||
B51-35 | Not Affected | - | |||
B51-80 | Not Affected | - | |||
B70-80 | Not Affected | - | |||
E31-70 | Not Affected | - | |||
E31-80 | Not Affected | - | |||
E40-80 | Not Affected | - | |||
E41-15 | Affected | Complete | 1UCN16WW | http://support.lenovo.com/downloads/DS113181 | 9/6/2016 |
E41-80 | Not Affected | - | |||
E50-80 | Not Affected | - | |||
E51-80 | Not Affected | - | |||
Edge2 1580 | Not Affected | - | |||
Flex 3-1130 | Not Affected | - | |||
Flex 3-1435 | Affected | Complete | BECN55WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Flex-Series/flex-3-1435/downloads/DS103214 | 8/31/2016 |
Flex 3-1470 | Affected | Complete | BDCN71WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Flex-Series/flex-3-1470/downloads/DS102775 | 8/31/2016 |
Flex 3-1480 | Not Affected | - | |||
Flex 3-1570 | Affected | Complete | BDCN71WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Flex-Series/flex-3-1470/downloads/DS102775 | 8/31/2016 |
Flex 3-1580 | Not Affected | - | |||
G40-80 | Not Affected | - | |||
G40-80m | Not Affected | - | |||
G41-35 | Affected | Complete | C3CN67WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-G-Series-laptops/g41-35/downloads/DS104847 | 8/31/2016 |
G50-80 | Not Affected | - | |||
G50-80 Touch | Not Affected | - | |||
G50-80m | Not Affected | - | |||
G51-35 | Affected | Complete | C3CN67WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-G-Series-laptops/g51-35/downloads/DS104847 | 8/31/2016 |
G70-35 | Affected | Complete | DECN43WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-G-Series-laptops/g70-35/downloads/DS118329 | 8/26/2016 |
G70-80 | Not Affected | - | |||
IdeaPad 100S-11IBY | Not Affected | - | |||
IdeaPad 100S-14IBR | Affected | Complete | E4CN34WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/100-series/100s-14ibr/downloads/DS105646 | 8/26/2016 |
IdeaPad 300-14IBR | Not Affected | - | |||
IdeaPad 300-14ISK | Not Affected | - | |||
IdeaPad 300-15IBR | Not Affected | - | |||
IdeaPad 300-15ISK | Not Affected | - | |||
IdeaPad 300-17ISK | Not Affected | - | |||
IdeaPad 300S-11IBR | Not Affected | - | |||
IdeaPad 305-14IBD | Not Affected | - | |||
IdeaPad 305-15IBD | Not Affected | - | |||
IdeaPad 305-15IBY | Not Affected | - | |||
IdeaPad 500-15ACZ | Not Affected | - | |||
K20 | Affected | Complete | ADCN54WW | Contact your local servicer or contact the Lenovo support center | 8/26/2016 |
K41-70 | Affected | Complete | C1CN31WW | Contact your local servicer or contact the Lenovo support center | 8/1/2016 |
Lenovo IdeaPad 310-14ISK | Not Affected | - | |||
Lenovo IdeaPad 310-15ISK | Not Affected | - | |||
Lenovo IdeaPad 510-15 ISK | Not Affected | - | |||
Lenovo N22 | Affected | Complete | 0YCN23WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-N-Series-laptops/n22/downloads/DS112192 | 8/31/2016 |
Lenovo Yoga 500-14IBD | Affected | Complete | BDCN71WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Yoga-Series/yoga-500-14ibd/downloads/DS102775 | 8/31/2016 |
Lenovo Yoga 500-14ISK | Not Affected | - | |||
Lenovo Yoga 500-15IBD | Affected | Complete | BDCN71WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Yoga-Series/yoga-500-15ibd/downloads/DS102775 | 8/31/2016 |
Lenovo Yoga 500-15ISK | Not Affected | - | |||
M41-70 | Affected | Complete | C1CN31WW | Contact your local servicer or contact the Lenovo support center | 8/1/2016 |
M41-80 | Not Affected | - | |||
M51-80 | Not Affected | - | |||
MIIX700-12ISK | Not Affected | - | |||
N22 Chromebook | Not Affected | - | |||
N41-80 | Not Affected | - | |||
N51-80 | Not Affected | - | |||
Nano B15 | Not Affected | - | |||
S41-35 | Affected | Complete | BECN55WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-S-Series-laptops/s41-35/downloads/DS103214 | 8/31/2016 |
S41-75 | Affected | Complete | BFCN59WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-S-Series-laptops/s41-75/downloads/DS105291 | 8/31/2016 |
XiaoXin 310-14ISK | Not Affected | - | |||
XiaoXin Air 13 | Not Affected | - | |||
Y700-14 ISK | Not Affected | - | |||
Y700-15ACZ | Not Affected | - | |||
Y700-15ISK | Not Affected | - | |||
Y700-15ISK 3D | Not Affected | - | |||
Y700-17ISK | Not Affected | - | |||
Y700Touch-15ISK | Not Affected | - | |||
Yoga 3 14 | Affected | Complete | BACNA0WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Yoga-Series/Yoga-3-1470/downloads/DS102769 | 8/26/2016 |
Yoga 300-11IBR | Not Affected | - | |||
Yoga 700-11ISK | Not Affected | - | |||
Yoga 700-14 | Not Affected | - | |||
Yoga 900 | Not Affected | - | |||
YOGA 900S | Not Affected | - | |||
Z50-75 | Affected | Complete | A4CN42WW | http://support.lenovo.com/us/en/products/Laptops-and-netbooks/Lenovo-Z-Series-laptops/Lenovo-Z50-75/downloads/DS100825 | 8/31/2016 |
Z51-70 | Not Affected | - |
Product | Status |
Lenovo Storage E1012/E1024 | Not Affected |
Lenovo Storage SBOD | Not Affected |
N3310 | Not Affected |
N4610 | Not Affected |
S2200/S3200 | Not Affected |
ThinkServer Storage SA120 | Not Affected |
Product | Status | Estimated Availability of BIOS Update | Minimum BIOS Version Required to Fix | Link to Update | Last Updated |
Flex System x240 M4 | Not Affected | − | |||
Flex System x240 M5 | Affected | 10/25/2016 | C4E126N | http://support.lenovo.com/downloads/DS118744 | 10/25/2016 |
Flex System x280 X6 | Affected | 10/25/2016 | N3E136K | http://support.lenovo.com/downloads/DS118757 | 10/25/2016 |
Flex System x440 M4 | Not Affected | − | |||
Flex System x480 X6 | Affected | 10/25/2016 | N3E136K | http://support.lenovo.com/downloads/DS118757 | 10/25/2016 |
Flex System x880 | Affected | 10/25/2016 | N3E136K | http://support.lenovo.com/downloads/DS118757 | 10/25/2016 |
NeXtScale nx360 M5 | Affected | 10/25/2016 | THE126N | http://support.lenovo.com/downloads/DS119014 | 10/25/2016 |
System x3500 M5 | Affected | 10/25/2016 | TAE126O | http://support.lenovo.com/downloads/DS118743 | 10/25/2016 |
System x3550 M5 | Affected | 10/25/2016 | TBE126O | http://support.lenovo.com/downloads/DS118743 | 10/25/2016 |
System x3650 M5 | Affected | 10/25/2016 | TCE1260 | http://support.lenovo.com/downloads/DS118759 | 10/25/2016 |
System x3750 M4 | Not Affected | − | |||
System x3850 X6 | Affected | 10/25/2016 | A9E136K | http://support.lenovo.com/downloads/DS118788 | 10/25/2016 |
System x3950 X6 | Affected | 10/25/2016 | A9E136K | http://support.lenovo.com/downloads/DS118788 | 10/25/2016 |
Product | Status | Estimated Availability of BIOS Update | Minimum BIOS Version Required to Fix | Link to Update | Last Updated |
BladeCenter HS22 | Not Affected | − | |||
BladeCenter HS22V | Not Affected | − | |||
BladeCenter HS23 | Not Affected | − | |||
BladeCenter HS23E | Not Affected | − | |||
BladeCenter HX5 | Not Affected | − | |||
Flex System x220 M4 | Not Affected | − | |||
Flex System x222 M4 | Not Affected | − | |||
Flex System x240 M4 | Not Affected | − | |||
Flex System x280 | Not Affected | − | |||
Flex System x280 X6 | Affected | Complete | ibm_fw_uefi_n2e120b-1.40_anyos_32-64 | https://www-945.ibm.com/support/fixcentral/systemx/selectFixes?parent=x280 | 10/20/2016 |
Flex System x440 M4 | Not Affected | − | |||
Flex System x480 | Not Affected | − | |||
Flex System x480 X6 | Affected | Complete | ibm_fw_uefi_n2e120b-1.40_anyos_32-64 | https://www-945.ibm.com/support/fixcentral/systemx/selectFixes?parent=x480 | 10/20/2016 |
Flex System x880 | Affected | Complete | ibm_fw_uefi_n2e120b-1.40_anyos_32-64 | https://www-945.ibm.com/support/fixcentral/systemx/selectFixes?parent=x880 | 10/20/2016 |
Flex System x880 X6 | Affected | Complete | ibm_fw_uefi_n2e120b-1.40_anyos_32-64 | https://www-945.ibm.com/support/fixcentral/systemx/selectFixes?parent=x880x6 | 10/20/2016 |
iDataPlex dx360 M2 | Not Affected | − | |||
iDataPlex dx360 M3 | Not Affected | − | |||
iDataPlex dx360 M4 | Not Affected | − | |||
iDataPlex dx360 M4 Water Cooled | Not Affected | − | |||
NeXtScale nx360 M4 | Not Affected | − | |||
System x3100 M4 | Not Affected | − | |||
System x3100 M5 | Not Affected | − | |||
System x3250 M4 | Not Affected | − | |||
System x3250 M5 | Not Affected | − | |||
System x3300 M4 | Not Affected | − | |||
System x3500 M2 | Not Affected | − | |||
System x3500 M3 | Not Affected | − | |||
System x3500 M4 | Not Affected | − | |||
System x3530 M4 | Not Affected | − | |||
System x3550 M2 | Not Affected | − | |||
System x3550 M3 | Not Affected | − | |||
System x3550 M4 | Not Affected | − | |||
System x3560 M2 | Not Affected | − | |||
System x3560 M3 | Not Affected | − | |||
System x3630 M3 | Not Affected | − | |||
System x3630 M4 | Not Affected | − | |||
System x3650 M3 | Not Affected | − | |||
System x3650 M4 | Not Affected | − | |||
System x3650 M4 BD | Not Affected | − | |||
System x3650 M4 HD | Not Affected | − | |||
System x3690 X5 | Not Affected | − | |||
System x3750 M4 | Not Affected | − | |||
System x3850 X5 | Not Affected | − | |||
System x3850 X6 | Affected | Complete | ibm_fw_uefi_a8e120c-1.30_anyos_32-64 | https://www-945.ibm.com/support/fixcentral/systemx/selectFixes?parent=System%2Bx3850 | 10/20/2016 |
System x3950 X5 | Not Affected | − | |||
System x3950 X6 | Affected | Complete | ibm_fw_uefi_a8e120c-1.30_anyos_32-64 | https://www-945.ibm.com/support/fixcentral/systemx/selectFixes?parent=System%2Bx3950 | 10/20/2016 |
Product | Status | Estimated Availability of BIOS Update | Minimum BIOS Version Required to Fix | Link to Update | Last Updated | |
ThinkPad 10 | Affected | Complete | N1AETB0W | http://support.lenovo.com/downloads/DS104930 | 9/9/2016 | |
ThinkPad 11e (Beema) | Affected | Complete | JIET29WW | http://support.lenovo.com/downloads/DS102504 | 11/29/2016 | |
ThinkPad 11e Chromebook/ThinkPad Yoga 11e Chromebook | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad 11e/Yoga 11e (Broadwell) | Affected | Complete | JHET61WW | http://support.lenovo.com/downloads/DS102664 | 7/28/2016 | |
ThinkPad 11e/Yoga 11e(Skylake) | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad 13 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad E450/E450c/E550/E550c | Affected | Complete | J5ET54WW | http://support.lenovo.com/downloads/DS101972 | 7/28/2016 | |
ThinkPad E455/E555 | Affected | Complete | HTET48WW | http://support.lenovo.com/downloads/DS100990 | 10/13/2016 | |
ThinkPad E460/E560/E560c/E560p | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad E465/E565 | Affected | Complete | R01ET34W | http://support.lenovo.com/downloads/DS105374 | 10/13/2016 | |
ThinkPad E470/E570 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad E475/E575 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad Edge E145 | Affected | Complete | HSET64WW | http://support.lenovo.com/downloads/DS036720 | 11/29/2016 | |
ThinkPad Edge E431/E531 | Affected | Complete | HEET50WW | http://support.lenovo.com/downloads/DS035124 | 10/13/2016 | |
ThinkPad Edge E440/E540 | Affected | Complete | J9ET9EWW | http://support.lenovo.com/downloads/DS037207 | 11/29/2016 | |
ThinkPad Edge E445/E545 | Affected | Complete | HRET27WW | http://support.lenovo.com/downloads/DS035512 | 10/2/2016 | |
ThinkPad Helix (20CG-20CH) | Affected | Complete | N17ET87W | http://support.lenovo.com/downloads/DS101505 | 7/28/2016 | |
ThinkPad Helix (3xxx) | Affected | Complete | GFET55WW | http://support.lenovo.com/downloads/DS034627 | 9/27/2016 | |
ThinkPad L430/L530 | Affected | Complete | G3ETA7WW | http://support.lenovo.com/downloads/DS029124 | 10/25/2016 | |
ThinkPad L440/L540 | Affected | Complete | J4ET87WW | http://support.lenovo.com/downloads/DS037206 | 11/1/2016 | |
ThinkPad L450 | Affected | Complete | JDET59WW | http://support.lenovo.com/downloads/DS102107 | 7/28/2016 | |
ThinkPad L460 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad L560 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad P40 Yoga | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad P50/P50s | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad P70 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad S1 Yoga (non-vPro) | Affected | Complete | GQET50WW | http://support.lenovo.com/downloads/DS038334 | 7/9/2016 | |
ThinkPad S1 Yoga (vPro) | Affected | Complete | B0ET35WW | http://support.lenovo.com/downloads/DS038334 | 9/9/2016 | |
ThinkPad S1 Yoga 12 | Affected | Complete | JEET74WW | http://support.lenovo.com/downloads/DS102265 | 7/28/2016 | |
ThinkPad S2 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad S3 Yoga 14 | Affected | Complete | JFET47WW | http://support.lenovo.com/downloads/DS101225 | 7/28/2016 | |
ThinkPad S3-S440 | Affected | Complete | J3ET67WW | http://support.lenovo.com/downloads/DS036070 | 11/1/2016 | |
ThinkPad S430 | Affected | Complete | GAETA2WW | http://support.lenovo.com/downloads/DS029726 | 9/9/2016 | |
ThinkPad S5 Yoga | Affected | Complete | N19ET50W | http://support.lenovo.com/downloads/DS102341 | 9/9/2016 | |
ThinkPad S5/E560p | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad S531 | Affected | Complete | GKET37WW | http://support.lenovo.com/downloads/DS035584 | 9/9/2016 | |
ThinkPad S540 | Affected | Complete | GPET68WW | http://support.lenovo.com/downloads/DS038373 | 9/6/2016 | |
ThinkPad T420, T420i | Affected | Complete | 83ET79WW | http://support.lenovo.com/us/downloads/DS018785 | 10/13/2016 | |
ThinkPad T420s, T420si | Affected | Complete | 8CET63WW | http://support.lenovo.com/downloads/DS014992 | 11/1/2016 | |
ThinkPad T430/T430i | Affected | Complete | G1ETB1WW | http://support.lenovo.com/downloads/DS029252 | 9/6/2016 | |
ThinkPad T430s/T430si | Affected | Complete | G7ETA6WW | http://support.lenovo.com/downloads/DS029724 | 10/2/2016 | |
ThinkPad T431s | Affected | Complete | GHET34WW | http://support.lenovo.com/downloads/DS034505 | 10/25/2016 | |
ThinkPad T440/T440s | Affected | Complete | GJET90WW | http://support.lenovo.com/downloads/ds035965 | 9/20/2016 | |
ThinkPad T440p | Affected | Complete | GLET84WW | http://support.lenovo.com/downloads/DS037575 | 10/2/2016 | |
ThinkPad T450/T450s | Affected | Complete | JBET61WW | http://support.lenovo.com/downloads/ds102109 | 9/20/2016 | |
ThinkPad T460/T460p/T460s | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad T520, T520i | Affected | Complete | 8AET66WW | http://support.lenovo.com/downloads/DS018810 | 11/1/2016 | |
ThinkPad T530/T530i | Affected | Complete | G4ETA7WW | http://support.lenovo.com/downloads/DS029246 | 9/19/2016 | |
ThinkPad T540/T540p | Affected | Complete | GMET76WW | http://support.lenovo.com/downloads/DS038147 | 9/9/2016 | |
ThinkPad T550 | Affected | Complete | N11ET39W | http://support.lenovo.com/downloads/DS102339 | 7/28/2016 | |
ThinkPad T560 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad Tablet 10 (32-bit) | Affected | Complete | GUET79WW | http://support.lenovo.com/downloads/DS041534 | 9/6/2016 | |
ThinkPad Tablet 10 (64-bit) | Affected | Complete | GWET43WW | http://support.lenovo.com/downloads/DS041804 | 9/9/2016 | |
ThinkPad Tablet 8 (32-bit) | Affected | Complete | GTET73WW | http://support.lenovo.com/downloads/DS040045 | 9/9/2016 | |
ThinkPad Tablet 8 (64-bit) | Affected | Complete | GYET35WW | http://support.lenovo.com/downloads/DS100744 | 9/9/2016 | |
ThinkPad Twist/Edge S230 | Affected | Complete | GDETB2WW | http://support.lenovo.com/downloads/DS032000 | 9/9/2016 | |
ThinkPad W520 | Affected | Complete | 8BET63WW | http://support.lenovo.com/downloads/DS018884 | 11/14/2016 | |
ThinkPad W530 | Affected | Complete | G5ETA6WW | http://support.lenovo.com/downloads/DS029169 | 9/20/2016 | |
ThinkPad W540/W541 | Affected | Complete | GNET80WW | http://support.lenovo.com/downloads/DS039077 | 9/9/2016 | |
ThinkPad W550s | Affected | Complete | N11ET39W | http://support.lenovo.com/downloads/DS102339 | 7/28/2016 | |
ThinkPad X1 (20GG-20GH) | Affected | Complete | 1.55 (N1LET55W) | http://support.lenovo.com/downloads/DS112372 | 9/14/2016 | |
ThinkPad X1 Carbon (20A7-20A8) | Affected | Complete | GRET49WW | http://support.lenovo.com/downloads/DS039782 | 9/9/2016 | |
ThinkPad X1 Carbon (20BS-20BT) | Affected | Complete | N14ET36W | http://support.lenovo.com/downloads/DS101975 | 9/6/2016 | |
ThinkPad X1 Carbon (20FB-20FC) | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad X1 Carbon (34xx) | Affected | Complete | G6ETB5WW | http://support.lenovo.com/downloads/DS030684 | 10/2/2016 | |
ThinkPad X1/Hybrid | Affected | Complete | 8MET71WW | http://support.lenovo.com/downloads/DS018205 | 11/14/2016 | |
ThinkPad X1 Yoga (20FR-20FQ) | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad X131e (AMD) | Affected | Complete | G9ETA2WW | http://support.lenovo.com/downloads/DS029771 | 10/25/2016 | |
ThinkPad X131e (Intel) | Affected | Complete | G8ETA5WW | http://support.lenovo.com/downloads/DS029771 | 10/25/2016 | |
ThinkPad X140e (AMD) | Affected | Complete | GSET65WW | http://support.lenovo.com/downloads/DS038561 | 10/2/2016 | |
ThinkPad X220/X220i/X220 Tablet | Affected | Complete | 8DET73WW | http://support.lenovo.com/downloads/DS018805 | 11/1/2016 | |
ThinkPad X230 Tablet | Affected | Complete | GCETA5WW | http://support.lenovo.com/downloads/ds029683 | 9/27/2016 | |
ThinkPad X230/X230i | Affected | Complete | G2ETA7WW | http://support.lenovo.com/downloads/DS029187 | 9/27/2016 | |
ThinkPad X230i Tablet | Affected | Complete | GCETA5WW | http://support.lenovo.com/downloads/ds029683 | 9/27/2016 | |
ThinkPad X230s/X231s | Affected | Complete | GGET27WW | http://support.lenovo.com/downloads/DS034847 | 9/6/2016 | |
ThinkPad X240/X240s | Affected | Complete | GIET86WW | http://support.lenovo.com/downloads/DS035950 | 9/6/2016 | |
ThinkPad X250 | Affected | Complete | N10ET44W | http://support.lenovo.com/downloads/DS102288 | 9/6/2016 | |
ThinkPad X260 | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad X260 Yoga (20FD-20FE-20GS-20GT) | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad Yoga 11e | Affected | Complete | N15ET67W | http://support.lenovo.com/downloads/DS041529 | 11/1/2016 | |
ThinkPad Yoga 12 | Affected | Complete | JEET74WW | http://support.lenovo.com/downloads/DS102265 | 7/28/2016 | |
ThinkPad Yoga 14 (20DM-20DN) | Affected | Complete | JFET47WW | http://support.lenovo.com/downloads/DS101225 | 10/13/2016 | |
ThinkPad Yoga 14 (Sharkbay) | Affected | Complete | JGET28WW |
|
11/29/2016 | |
ThinkPad Yoga 15 | Affected | Complete | N19ET50W | http://support.lenovo.com/downloads/DS102341 | 7/28/2016 | |
ThinkPad Yoga 460 (20EL-20EM) | Not Affected | - | - | - | 7/9/2016 | |
ThinkPad X1 Tablet (20GG-20GH) | Not Affected | - | - | - | 7/9/2016 |
Product | Status | Estimated Availability of BIOS Update | Minimum BIOS Version Required to Fix | Link to Update |
ThinkServer DC5000 | Not Affected | |||
ThinkServer DC5100 | Not Affected | |||
ThinkServer RD340 | Affected | Complete | A0TSC1A | http://support.lenovo.com/us/en/products/Servers/ThinkServer-rack-servers/ThinkServer-RD340 |
ThinkServer RD350 | Not Affected | - | ||
ThinkServer RD350X | Not Affected | |||
ThinkServer RD430X | Not Affected | |||
ThinkServer RD440 | Affected | Complete | A0TSC1A | http://support.lenovo.com/us/en/products/Servers/ThinkServer-rack-servers/ThinkServer-RD440 |
ThinkServer RD440X | Not Affected | |||
ThinkServer RD450 | Not Affected | - | ||
ThinkServer RD450X | Not Affected | |||
ThinkServer RD540 | Affected | Complete | A1TSC1A | http://support.lenovo.com/us/en/products/Servers/ThinkServer-rack-servers/ThinkServer-RD540 |
ThinkServer RD550 | Not Affected | - | ||
ThinkServer RD640 | Affected | Complete | A1TSC1A | http://support.lenovo.com/us/en/products/Servers/ThinkServer-rack-servers/ThinkServer-RD640 |
ThinkServer RD640X | Not Affected | |||
ThinkServer RD650 | Not Affected | - | ||
ThinkServer RQ750 | Not Affected | - | ||
ThinkServer RQ940 | Affected | Complete | S4L_3A17 | http://support.lenovo.com.cn/lenovo/wsi/Modules/DriverDownLoadServer.aspx |
ThinkServer RS140 | Not Affected | - | ||
ThinkServer SD330 | Not Affected | |||
ThinkServer SS440 | Not Affected | |||
ThinkServer TD340 | Affected | Complete | A3TSC1A | http://support.lenovo.com/us/en/products/Servers/ThinkServer-tower-servers/ThinkServer-TD340 |
ThinkServer TD350 | Not Affected | - | ||
ThinkServer TS140 | Not Affected | - | ||
ThinkServer TS150 | Not Affected | - | ||
ThinkServer TS240 | Not Affected | - | ||
ThinkServer TS250 | Not Affected | - | ||
ThinkServer TS440 | Not Affected | - | ||
ThinkServer TS450 | Not Affected | - | ||
ThinkServer TS540 | Not Affected | - | ||
ThinkServer TS550 | Not Affected | - |
Product | Status |
ThinkStation C30 (type 1095-1096-1097) | Not Affected |
ThinkStation C30 (type 1136-1137) | Not Affected |
ThinkStation D30 (type 4223-4228-4229) | Not Affected |
ThinkStation D30 (type 4353-4354) | Not Affected |
ThinkStation E31 | Not Affected |
ThinkStation E32 | Not Affected |
ThinkStation P300 | Not Affected |
ThinkStation P310 | Not Affected |
ThinkStation P410 | Not Affected |
ThinkStation P500 | Not Affected |
ThinkStation P510 | Not Affected |
ThinkStation P700 | Not Affected |
ThinkStation P710 | Not Affected |
ThinkStation P900 | Not Affected |
ThinkStation P910 | Not Affected |
ThinkStation S30 (type 0567-0568-0569-0606) | Not Affected |
ThinkStation S30 (type 4351-4352) | Not Affected |
Your feedback helps to improve the overall experience