Vulnerability index

Browse CVEs

102 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

330 14ast Firmware MEDIUM 6.7
CVE-2020-8322

A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitr…

Mitigation only
Fix from $1,600 2020-06-09
330 14ast Firmware MEDIUM 6.7
CVE-2020-8323

A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models…

Mitigation only
Fix from $1,600 2020-06-09
B50 10 Firmware CRITICAL 9.8
CVE-2015-5684

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly…

Mitigation only
Fix from $2,300 2020-03-27
Xclarity Administrator MEDIUM 6.0
CVE-2019-19756

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of manag…

Mitigation only
Fix from $1,600 2020-03-13
Thinkcentre E93 Firmware MEDIUM 5.5
CVE-2019-6190

Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and …

Mitigation only
Fix from $1,600 2020-02-14
Customer Engagement Service HIGH 7.8
CVE-2019-6184

A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.

No fix yet
Fix from $1,950 2019-11-20
Paper HIGH 7.8
CVE-2019-6191

A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.

Mitigation only
Fix from $1,950 2019-11-20
510 15ikl Firmware CRITICAL 9.8
CVE-2019-6188

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W…

Mitigation only
Fix from $2,300 2019-11-12
510 15ikl Firmware MEDIUM 6.4
CVE-2019-6170

A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo Th…

Mitigation only
Fix from $1,600 2019-11-12
510 15ikl Firmware MEDIUM 6.4
CVE-2019-6172

A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo Th…

Mitigation only
Fix from $1,600 2019-11-12
Solution Center CRITICAL 9.8
CVE-2019-6177

A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standa…

Mitigation only
Fix from $2,300 2019-08-21
Px12 350r Firmware MEDIUM 5.3
CVE-2019-6178

An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through t…

Mitigation only
Fix from $1,600 2019-08-19
Yoga 700 11isk Firmware HIGH 7.8
CVE-2019-6165

A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended s…

Mitigation only
Fix from $1,950 2019-08-19
20f1 Firmware MEDIUM 6.8
CVE-2019-6171

A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical ac…

Mitigation only
Fix from $1,600 2019-08-19
Bladecenter Hs22 Firmware MEDIUM 6.1
CVE-2019-6159

A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Mana…

Mitigation only
Fix from $1,600 2019-08-19
Storcenter Px12 450r Firmware CRITICAL 9.8
CVE-2018-9079

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DO…

Mitigation only
Fix from $2,300 2018-09-28
Storcenter Px12 450r Firmware HIGH 8.8
CVE-2018-9078

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to uploa…

Mitigation only
Fix from $1,950 2018-09-28
Storcenter Px12 450r Firmware HIGH 8.8
CVE-2018-9082

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated use…

Mitigation only
Fix from $1,950 2018-09-28
Storcenter Px12 450r Firmware MEDIUM 5.9
CVE-2018-9080

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into …

Mitigation only
Fix from $1,600 2018-09-28
Thinkcentre M710s Firmware HIGH 7.5
CVE-2017-3771

System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing …

Mitigation only
Fix from $1,950 2017-10-26
Thinkpad 10 Ella 2 Bios HIGH 7.8
CVE-2017-3756

A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attac…

Mitigation only
Fix from $1,950 2017-08-18
Ideacentre 300 20ish Firmware MEDIUM 6.8
CVE-2017-3753

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnera…

Mitigation only
Fix from $1,600 2017-08-10
Bios MEDIUM 6.7
CVE-2017-3754

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical …

Mitigation only
Fix from $1,600 2017-07-17
Nerve Center MEDIUM 5.5
CVE-2017-3747

Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected…

Mitigation only
Fix from $1,600 2017-06-29
Lenovo Service Bridge HIGH 8.8
CVE-2016-8229

A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server…

Mitigation only
Fix from $1,950 2017-06-04
Lenovo Service Bridge HIGH 7.8
CVE-2016-8228

In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.

Mitigation only
Fix from $1,950 2017-06-04
Lenovo Service Bridge HIGH 7.5
CVE-2016-8230

In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and produc…

Mitigation only
Fix from $1,950 2017-06-04
Lenovo Service Bridge HIGH 7.5
CVE-2016-8231

In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an a…

Mitigation only
Fix from $1,950 2017-06-04
Active Protection System MEDIUM 5.5
CVE-2017-3740

In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which…

Mitigation only
Fix from $1,600 2017-06-04
Updates HIGH 8.1
CVE-2016-8237

Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2017-04-10