Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xclarity Administrator MEDIUM 5.3
CVE-2017-3764

A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated u…

Fix: 1.4.0+
Fix from $1,600 2017-11-30
Thinkcentre M710s Firmware HIGH 7.5
CVE-2017-3771

System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing …

Mitigation only
Fix from $1,950 2017-10-26
Service Framework CRITICAL 9.8
CVE-2017-3758

Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.

Patch available
Fix from $2,300 2017-10-17
Service Framework CRITICAL 9.8
CVE-2017-3761

The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this …

Patch available
Fix from $2,300 2017-10-17
Service Framework HIGH 8.1
CVE-2017-3759

The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to ma…

Patch available
Fix from $1,950 2017-10-17
Service Framework HIGH 8.1
CVE-2017-3760

The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded application…

Patch available
Fix from $1,950 2017-10-17
System Update HIGH 7.8
CVE-2015-6971

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUSer…

Fix: after 5.06.0034
Fix from $1,950 2017-10-03
Fingerprint Manager MEDIUM 6.7
CVE-2015-3321

Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain pri…

Fix: after 8.01.41
Fix from $1,600 2017-10-03
Xclarity Administrator HIGH 8.8
CVE-2017-3770

Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functio…

Fix: after 1.3.1
Fix from $1,950 2017-09-22
Xclarity Administrator MEDIUM 6.7
CVE-2017-3763

An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA …

Fix: after 1.3.1
Fix from $1,600 2017-09-22
Thinkpad Usb 3.0 Ethernet Adapter Driver HIGH 7.8
CVE-2017-3746

ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that c…

Patch available
Fix from $1,950 2017-08-29
Thinkpad 10 Ella 2 Bios HIGH 7.8
CVE-2017-3756

A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attac…

Mitigation only
Fix from $1,950 2017-08-18
Thinkpad Compact Usb Keyboard Driver HIGH 7.8
CVE-2017-3751

An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5…

Patch available
Fix from $1,950 2017-08-10
Ideacentre 300 20ish Firmware MEDIUM 6.8
CVE-2017-3753

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnera…

Mitigation only
Fix from $1,600 2017-08-10
Bios MEDIUM 6.7
CVE-2017-3754

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical …

Mitigation only
Fix from $1,600 2017-07-17
Nerve Center MEDIUM 5.5
CVE-2017-3747

Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected…

Mitigation only
Fix from $1,600 2017-06-29
Xclarity Administrator HIGH 7.8
CVE-2017-3745

In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password …

Fix: after 1.2.2
Fix from $1,950 2017-06-20
Advanced Settings Utility HIGH 7.5
CVE-2017-3743

If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utili…

Fix: after 10.2
Fix from $1,950 2017-06-20
Integrated Management Module Firmware MEDIUM 6.5
CVE-2017-3744

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture …

Fix: after 6.19
Fix from $1,600 2017-06-20
Mouse Suite HIGH 7.8
CVE-2015-4596

Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.

Fix: after 6.72
Fix from $1,950 2017-06-13
Lenovo Service Bridge HIGH 8.8
CVE-2016-8229

A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server…

Mitigation only
Fix from $1,950 2017-06-04
Lenovo Service Bridge HIGH 7.8
CVE-2016-8228

In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.

Mitigation only
Fix from $1,950 2017-06-04
Lenovo Service Bridge HIGH 7.5
CVE-2016-8230

In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and produc…

Mitigation only
Fix from $1,950 2017-06-04
Lenovo Service Bridge HIGH 7.5
CVE-2016-8231

In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an a…

Mitigation only
Fix from $1,950 2017-06-04
Active Protection System MEDIUM 5.5
CVE-2017-3740

In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which…

Mitigation only
Fix from $1,600 2017-06-04
Solution Center HIGH 7.8
CVE-2016-1876

The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.

Fix: after 3.3.0001
Fix from $1,950 2017-05-23
Lenovo System Update HIGH 7.8
CVE-2015-8110

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to…

Fix: after 5.07.0013
Fix from $1,950 2017-04-24
Lenovo System Update HIGH 7.0
CVE-2015-8109

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_…

Fix: after 5.07.0013
Fix from $1,950 2017-04-24
Updates HIGH 8.1
CVE-2016-8237

Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2017-04-10
Customer Care Software Development Kit HIGH 7.8
CVE-2016-8235

Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with …

Fix: after 2.0.16
Fix from $1,950 2017-04-10