LOW
This advisory does not detail a security vulnerability but rather operational inefficiency. The severity is LOW as it concerns the management and accessibility of recovery images, which do not directly impact system security.

This advisory details the challenge of creating bootable media for multiple Lenovo ThinkPad recovery images without relying on individual USB keys. The attack vector involves potential difficulties in managing and accessing these images efficiently. Impact includes time-consuming manual processes and lack of flexibility in handling multiple recovery scenarios. Sysadmins and IT professionals who manage large fleets of Lenovo ThinkPads are affected.

Affected Systems
  • Lenovo ThinkPad recovery tools
Affected Versions: All versions
Remediation
  • Use a multi-boot USB tool compatible with UEFI that can handle custom ISOs or bootable images, such as iVentoy.
  • Convert Lenovo's proprietary recovery image format to an ISO using available conversion tools if possible.
  • Create a custom bootloader menu that allows selection of different recovery images at boot time.
Source →