Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 5

-----------------------------------------------------------------------

Software name BIOS Update Utility


Supported models System Name
ThinkServer TS140
ThinkServer TS240
ThinkServer TS440
ThinkServer TS540

Operating system
Please refer to https://lenovopress.com/osig

Version DIA

Issue date Sep. 16, 2021

----------------------------------------------------------------------

----------------------------------------------------------------------
WHAT THIS PACKAGE DOES
----------------------------------------------------------------------

This BIOS update package enables you to update the server BIOS.

----------------------------------------------------------------------
Version history
----------------------------------------------------------------------
<Complete version history of released code>

Summary of changes
where: < > Version number
[Important] Important update
(New) New function or enhancement
(Fix) Correction to existing function

<DIA>
-[Important] Enhancement to address security vulnerability CVE-2020-10713
<DDA>
-(Fix)Fixed a chipsec test error.
<DCA>
-[Important] Enhancement to address security vulnerability CVE-2020-0543,
CVE-2020-0548, CVE-2020-0549
<D9A>
-Security fix to address CVE-2019-0151
(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0151).
<D7A>
-Update the CPU Microcode M32306C3_00000027.

<D3A> -(Fix) Add ";" character on password help message.

<D0A> -(Fix) Update UefiNetworkStack II to 27 for Open SSL issue.


<CZA>
-Update the CPU Microcode M32306C3_00000025.
<CXA>
-[Important] Update ME FW to 9.1.43.3004.
<CWA>
-(Fix)Security fix to address CVE-2017-5715 (http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2017-5715).
<CTA>
-(Fix)Roll back the CPU Microcode to M32306C3_00000022.
-(Fix)Modify BIOS update script. The CKA can't upgrade and downgrade, if
you want to update BIOS from CKA,
it will show "BIOS version error, please contact Lenovo service!" to
forbid BIOS update.
But if you want to update BIOS from other BIOS version(except CKA), it
will normal update BIOS.
<CRA>
-(Fix)Fix side effect for Pre-Boot DMA Protections security issue.
-(Fix)Update UefiNetworkStack II to 23 for Open SSL issue.
<COA>
-(Fix)Fix side effect for Pre-Boot DMA Protections security issue.
-Update the CPU Microcode M32306C3_00000023.
<CNA>
-(Fix)Fix security issue: Pre-Boot DMA Protections.
-[Important] Update ME FW to 9.1.42.3002.
<CMA>
-(Fix)Fix CKA downgrade hang.
<CKA>
-(Fix)Fix intel SPI security issue.
<CJA>
-Update Intel RSTe to 4.6.
<CIA>
-(Fix)Fix SMI#90 issue for Chipsec 1.3.1 FUZZ test.
<CHA>
-(Fix)Fix PSIRT issue - PRx Protection.
-(Fix)Update UefiNetworkStack II to 22 for Open SSL issue.
<CFA>
-[Important] Update includes security fixes.
<CEA>
-[Important] Update includes security fixes.
<CDA>
-Update the CPU Microcode M32306C3_00000022
-[Important] Update includes security fixes.
<CBA>
-Update the CPU Microcode M32306C3_00000021
-[Important] Update includes security fixes.
-Fix the issue that system may not find OS on Intel RSTe RAID if you do not
install any keyboard.
<C8A>
-[Important] Update includes security fixes.
<C3A>
-Fix some SMBIOS related issues.
-Fix boot sequence issues.
-Disable ASPM.
<C2A>
-Fix some SMBIOS related issues.
-Security fix openssl vulnerability CVE-2016-0701, CVE-2015-3197.
-update SMIFLASH module to v30
<C0A>
-Security fix disables AMT USB Provisioning when AMT is disabled. Refer to
Lenovo Security Advisory LEN-3556 for more information.
-remove smbios 1394 device
<B7A>
-Add fixed to remove f10 hardware diagnostic string.
<B5A>
-Update Intel RSTe 4.3 pre-OS binary.
-fix TxT init ACM.
<B3A>
-Fix Turbo mode issue.
<B2A>
-Update to support new CPU.
<A5A>
-Change the POST 0199 error behavior.
<99A>
-Add "Ramaxel Technology" support to "Manufacturer" field of "Memory
Device" in SMBIOS.
<98A>
-Update Intel VBIOS to version 1030.
<97A>
-Fix the issue that system may not find OS on LSI 9240 RAID in some
conditions.
-Fix some Power-On Password related issues.
<92A>
-Fix some SMBIOS related issues.
-Update the CPU Microcode to Revision M32306C3_0000001c.
<91A>
-Fix some SMBIOS related issues.
-Fix the WOL issue.
-Update the CPU Microcode to Revision M32306C3_00000019.
<89A>
-Fix some SMBIOS related issues.
<88A>
-Add Haswell-Refresh CPU support.
-Fix the issue that system might hang if the keyboard is connected through
a KVM switch and the switch is powered up at the same time with the system.
<82A>
-Fix the issue that system may stop boot when loading Citrix XenServer OS.
<81A>
-Fix the issue that some USB devices may not be recognized correctly during
boot.
-Fix the issue that system may hang while trying to boot from some models
of USB storages formatted as NTFS.
<70A>
-Fix the issue that system may hang during boot if system memory size is
decreased.
<68A>
-Add support for Windows 2012R2.
-Fix an issue that the USB port cannot be disabled via WMI.
-Update Intel TXT ACM module to Version 1.5.0
-Update CPU microcode to Revision M32306C3_00000017(08/16/2013).
<48A>
-Update CPU microcode to Revision M32306C3_00000016(08/07/2013).
-Update the VBIOS to version 2177 and GOP to version 5.0.1034.
-Fix the PCI slot controller can't be seen in windows device manager with
low probability issue.
-Fix the issue that USB 3.0 key still can be used in Windows after
disabling the according USB port in BIOS setup.
-BIOS will indetify the USB disk that has the capacity larger than 32G as a
USB HDD.
<40A>
-First Release version.

----------------------------------------------------------------------
INSTALLATION INSTRUCTIONS
----------------------------------------------------------------------
To update the server BIOS using this BIOS update package, you can select Command
Line Mode or User Interface Mode:

Attention: Do not turn off your server when updating the BIOS, otherwise the
BIOS will fail to be updated and the system will fail to restart.

Command Line Mode:


1. Download the package,copy the 'BIOSWIN32' or 'BIOSWIN64' package to C:\ .
2. Open folder "C:\Windows\System32", locate the file "cmd.exe". Right-click on
this application, select "Run as administrator" to open the "Command Prompt" with
Administrator privilege.
3. Input command to enter folder C:\BIOSWIN32 or C:\BIOSWIN64.
4. Then input command "flash.bat" to start flash process.
5. System will automatically reboot and start the update process. Do not power off
or restart the system during this procedure!
6. After the flash update completes, system will automatically reboot.

Graphic User Interface Mode:


1. Right click afuwingui.exe icon and select to run as administrator.
2. When the message "To ensure that no other program interferes with the BIOS
update process, it is recommended to close all other programs before continue."
pops up, click "OK" to start the update process.
3. System will automatically reboot and start the update process.Do not power off
or restart the system during this procedure!
4. After the flash update completes, system will automatically reboot.

----------------------------------------------------------------------
Limitations and considerations
----------------------------------------------------------------------
Note:
If the user want to downgrade the BIOS in the command Line Mode from the level
higher than or equal to 88A to an older level which is lower than 88A,
below steps should be taken to avoid the BIOS corruption:
1. Download the latest package,copy the 'BIOSWIN32' or 'BIOSWIN64' package to C:\ .
2. Copy the BIOS file IMAGEFB.ROM from the older package and replace the
IMAGEFB.ROM in the latest "BIOSWIN32" or "BIOSWIN64".
3. Open folder "C:\Windows\System32", locate the file "cmd.exe". Right-click on
this application, select "Run as administrator" to open the "Command Prompt" with
Administrator privilege.
4. Input command to enter folder C:\BIOSWIN32 or C:\BIOSWIN64.
5. Then input command "flash.bat" to start flash process.
6. System will automatically reboot and start the update process. Do not power off
or restart the system during this procedure!
7. After the flash update completes, system will automatically reboot.

----------------------------------------------------------------------
Open source
----------------------------------------------------------------------

This product contains open source code in the compiled form.


Contact Lenovo support for information about obtaining the original
source code.

----------------------------------------------------------------------
Trademarks and notices
----------------------------------------------------------------------

The following terms are trademarks of Lenovo in the United States,


other countries, or both:

ThinkServer

Intel is a registered trademarks of Intel Corporation or its subsidiaries


in the United States and other countries.

Other company, product, and service names may be trademarks or service


marks of others.

LENOVO PROVIDES THIS PUBLICATION "AS IS" WITHOUT WARRANTY OF ANY KIND,
EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
WARRANTIES OF NON-INFRINGEMENT, MERCHANTABILITY OR FITNESS FOR A
PARTICULAR PURPOSE.

Some jurisdictions do not allow disclaimer of express or implied


warranties in certain transactions, therefore, this statement may not
apply to you. This information could include technical inaccuracies
or typographical errors. Changes are periodically made to the
information herein; these changes will be incorporated in new editions
of the publication. Lenovo may make improvements and/or changes in
the product(s) and/or the program(s) described in this publication at
any time without notice.

BY FURNISHING THIS DOCUMENT, LENOVO GRANTS NO LICENSES TO ANY PATENTS


OR COPYRIGHTS.

(C) Copyright Lenovo 2008-2021. All rights reserved.

You might also like