Facebook Twitter LinkedIn RSS
    Trending
    • Charly Boy: Leo Stan Ekeh advised me to set up a foundation and avoid activism
    • Lawyer to sue MTN, Airtel, Glo, 9mobile, DStv over expiring data, subscriptions
    • Truecaller: 51% of unknown calls in Nigeria flagged as spam as trust in unknown numbers declines
    • WhatsApp: Why end-to-end encrypted messages can still be used as court evidence
    • Enugu launches TradEX programme to support 1,000 SMEs with digital trade
    • MTN wins 66% of Nigerians switching networks as 9mobile loses over 3,200 customers in 2026 Q1
    • Nigerian Minister to unveil ASUS flagship store in West Africa
    • Nigeria needs to translate emerging technologies to practical solutions
    Facebook Twitter LinkedIn
    ITPulse.com.ngITPulse.com.ng
    • News
    • Interviews
    • Blogs
    • Analysis
    • Opinion
    • Videos
    • Press Releases
    • Pictures
    • Advertise
    ITPulse.com.ngITPulse.com.ng
    Home»News»Update firmware in Lenovo products, NCC-CSIRT urges Nigerians
    News 2 Mins Read

    Update firmware in Lenovo products, NCC-CSIRT urges Nigerians

    mmBy ITPulseSeptember 30, 2022
    Facebook Twitter WhatsApp Pinterest LinkedIn Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Following several vendor vulnerabilities in some Lenovo products, which could lead to information disclosure, privilege escalation, and denial of service, the Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT), has urged Nigerians to update the firmware in their Lenovo products.

    In its recent advisory, NCC-CSIRT rated the probability of vulnerability as high with an equally high damage potential.

    The advisory cited the Lenovo report, first published in the second week of this month, indicating that the vulnerabilities are caused by flaws in the System Management Interrupt (SMI) Set BIOS Password SMI Handler, other systems used to configure platform settings over Windows Management Instrumentation (WMI), and a buffer overflow flaw in WMI SMI Handler.

    The vulnerabilities primarily affect Lenovo Products (Desktop, Desktop-All in One, Hyperscale, Lenovo Notebook, Smart Office, Storage, ThinkAgile, ThinkPad, ThinkServer, ThinkStation, and ThinkSystem).

    Successful exploitation of the vulnerabilities could allow an authenticated local attacker to bypass security restrictions, gain elevated privileges and execute arbitrary code on the targeted system. The attacker could also send a specially crafted request to the targeted user to gain sensitive information, which could result in unauthorized Information disclosure, privilege escalation and denial of service on the targeted system.

    According to NCC-CSIRT, the solution to addressing the vulnerabilities is for users to update their system firmware to the newer version(s) indicated for their product model.

    The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large. The CSIRT also works collaboratively with the Nigeria Computer Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

    Cybersecurity awareness Firmware
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    mm
    ITPulse
    • Website
    • Facebook
    • Twitter
    • LinkedIn

    ITPulse is a wholly information technology communication (ICT) news website, with a special focus on the African continent. The website provides up-to-date biz-tech news, analysis and comprehensive and thorough insight into the continent's ICT terrain

    Related Posts

    Lawyer to sue MTN, Airtel, Glo, 9mobile, DStv over expiring data, subscriptions

    July 31, 2026

    Truecaller: 51% of unknown calls in Nigeria flagged as spam as trust in unknown numbers declines

    July 31, 2026

    WhatsApp: Why end-to-end encrypted messages can still be used as court evidence

    July 31, 2026

    Leave A Reply Cancel Reply

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Latest Posts

    Charly Boy: Leo Stan Ekeh advised me to set up a foundation and avoid activism

    August 3, 2026

    Lawyer to sue MTN, Airtel, Glo, 9mobile, DStv over expiring data, subscriptions

    July 31, 2026

    Truecaller: 51% of unknown calls in Nigeria flagged as spam as trust in unknown numbers declines

    July 31, 2026
    About
    About

    Itpulse.com.ng is a wholly information technology communication (ICT) news website, with special focus on the African continent. The website provides up-to-date biz-tech news, analysis and a comprehensive and thorough insight info the continent's ICT terrain.

    Contact us: editorial@itpulse.com.ng

    Facebook Twitter LinkedIn RSS
    Latest Posts

    Charly Boy: Leo Stan Ekeh advised me to set up a foundation and avoid activism

    August 3, 2026

    Lawyer to sue MTN, Airtel, Glo, 9mobile, DStv over expiring data, subscriptions

    July 31, 2026

    Truecaller: 51% of unknown calls in Nigeria flagged as spam as trust in unknown numbers declines

    July 31, 2026
    Popular Posts

    Consent is a distributed systems problem: Architecting token revocation and schema versioning for Nigeria’s open banking go-live

    October 24, 2025

    Truecaller: 51% of unknown calls in Nigeria flagged as spam as trust in unknown numbers declines

    July 31, 2026

    WhatsApp: Why end-to-end encrypted messages can still be used as court evidence

    July 31, 2026
    © 2017 - 2026 Itpulse.
    • Terms & Conditions
    • Privacy Policy
    • Advertise
    • Contact Us

    Type above and press Enter to search. Press Esc to cancel.