Vulnerability index

Browse CVEs

102 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Thinkpad T15 Gen 2 Firmware HIGH 7.8
CVE-2023-4030

A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure…

Mitigation only
Fix from $1,950 2023-08-17
13w Yoga Firmware MEDIUM 6.7
CVE-2023-4028

A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local…

Mitigation only
Fix from $1,600 2023-08-17
Legion 5 Pro 16iah7h Firmware MEDIUM 6.7
CVE-2023-34419

A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and e…

Mitigation only
Fix from $1,600 2023-08-17
Nextscale N1200 Enclosure Firmware MEDIUM 6.3
CVE-2023-2993

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited numb…

Mitigation only
Fix from $1,600 2023-06-26
Nextscale N1200 Enclosure Firmware HIGH 7.5
CVE-2023-2992

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted …

Mitigation only
Fix from $1,950 2023-06-26
Thinkpad E14 Firmware MEDIUM 6.7
CVE-2023-2290

A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute ar…

Mitigation only
Fix from $1,600 2023-06-26
Ideacentre C5 14imb05 Firmware HIGH 7.8
CVE-2022-48181

An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate…

Mitigation only
Fix from $1,950 2023-06-05
Ideacentre Aio 3 21itl7 Firmware HIGH 7.8
CVE-2022-48188

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local ac…

Mitigation only
Fix from $1,950 2023-06-05
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2022-40137

A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary c…

Mitigation only
Fix from $1,600 2023-01-30
Ideapad Y700 14isk Firmware MEDIUM 6.7
CVE-2022-3432

A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an at…

Mitigation only
Fix from $1,600 2023-01-26
Thinkbook 14 Iml Firmware HIGH 7.8
CVE-2022-1891

A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrar…

Mitigation only
Fix from $1,950 2023-01-26
100e 2nd Gen Firmware HIGH 7.8
CVE-2022-1892

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrar…

Mitigation only
Fix from $1,950 2023-01-26
Thinkbook 14 Iml Firmware HIGH 7.8
CVE-2022-1890

A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Mitigation only
Fix from $1,950 2023-01-26
D330 10igl Firmware MEDIUM 6.7
CVE-2022-3430

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify s…

Mitigation only
Fix from $1,600 2023-01-23
A340 22icb Firmware MEDIUM 6.7
CVE-2021-4211

A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models…

Mitigation only
Fix from $1,600 2022-04-22
Thinkpad 11e Firmware MEDIUM 6.7
CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some…

Mitigation only
Fix from $1,600 2022-04-22
Thinkpad X1 Fold Gen 1 Firmware MEDIUM 6.7
CVE-2022-1108

A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploite…

Mitigation only
Fix from $1,600 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3970

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with…

Mitigation only
Fix from $1,600 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3971

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included…

Mitigation only
Fix from $1,600 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3972

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deacti…

Mitigation only
Fix from $1,600 2022-04-22
Ideacentre C5 14mb05 Firmware MEDIUM 6.8
CVE-2021-3519

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Dev…

Mitigation only
Fix from $1,600 2021-11-12
Thinkcentre E93 Firmware MEDIUM 6.7
CVE-2021-3719

A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCent…

Mitigation only
Fix from $1,600 2021-11-12
Ideapad 1 11ada05 Firmware MEDIUM 6.8
CVE-2021-3614

A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain co…

No fix yet
Fix from $1,600 2021-07-16
Bios MEDIUM 6.7
CVE-2021-3452

A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated p…

Mitigation only
Fix from $1,600 2021-07-16
Notebook Firmware MEDIUM 6.7
CVE-2020-8354

A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code …

Mitigation only
Fix from $1,600 2020-11-11
Bladecenter Hs23 Firmware MEDIUM 6.4
CVE-2020-8332

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may al…

Mitigation only
Fix from $1,600 2020-10-14
Enterprise Network Disk MEDIUM 6.1
CVE-2020-8347

A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could…

Mitigation only
Fix from $1,600 2020-09-24
Enterprise Network Disk MEDIUM 6.1
CVE-2020-8348

A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could …

Mitigation only
Fix from $1,600 2020-09-24
Thinkpad T495s Firmware MEDIUM 6.8
CVE-2020-8334

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized a…

Mitigation only
Fix from $1,600 2020-06-09
130 14ast Firmware MEDIUM 6.7
CVE-2020-8321

A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models…

Mitigation only
Fix from $1,600 2020-06-09