PT-2024-1819 · Lenovo · Lenovo Thinksystem Sr670V2

Published

2024-02-13

·

Updated

2025-07-23

·

CVE-2024-23591

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lenovo ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023
Description The issue is related to Lenovo ThinkSystem SR670V2 servers being left in Manufacturing Mode, which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration settings. The server's NIST SP 800-193-compliant Platform Firmware Resiliency (PFR) security subsystem significantly mitigates this issue. The vulnerability is also described as being caused by a desynchronization of BIOS/UEFI and ME states due to the use of an unreleased configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-01562
CVE-2024-23591

Affected Products

Lenovo Thinksystem Sr670V2