Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thinkserver Firmware HIGH 7.5
CVE-2016-8236

Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions ea…

Fix: after 3.76.208
Fix from $1,950 2017-03-03
Xclarity Administrator CRITICAL 9.8
CVE-2016-8233

Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form…

Fix: after 1.2.1
Fix from $2,300 2017-03-01
Edge Keyboard Driver HIGH 7.8
CVE-2016-8225

Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code …

Fix: after 1.20
Fix from $1,950 2017-01-26
Transition HIGH 7.8
CVE-2016-8227

Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local users to …

Mitigation only
Fix from $1,950 2017-01-26
Xclarity Administrator HIGH 7.0
CVE-2016-8221

Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/outp…

Fix: after 1.1.1
Fix from $1,950 2017-01-12
System Interface Foundation HIGH 7.8
CVE-2016-8223

During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software insta…

Fix: after 1.0.66.0
Fix from $1,950 2016-11-29
Bios HIGH 7.8
CVE-2016-5247

The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer…

Mitigation only
Fix from $1,950 2016-09-22
Bios Efi Driver HIGH 8.2
CVE-2016-5729

Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2016-06-30
Solution Center HIGH 7.8
CVE-2016-5249

Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Se…

Fix: after 3.3.002
Fix from $1,950 2016-06-30
Solution Center MEDIUM 5.5
CVE-2016-5248

The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via …

Fix: after 3.3.002
Fix from $1,600 2016-06-30
Accelerator Application HIGH 7.5
CVE-2016-3944

UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi…

Mitigation only
Fix from $1,950 2016-06-03
Shareit MEDIUM 6.1
CVE-2016-4783

Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web scr…

Mitigation only
Fix from $1,600 2016-05-23
Shareit HIGH 8.8
CVE-2016-4782

Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent sc…

Mitigation only
Fix from $1,950 2016-05-23
Emc Firmware MEDIUM 5.3
CVE-2015-8108

The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r…

Mitigation only
Fix from $1,600 2016-04-12
Fingerprint Manager HIGH 7.8
CVE-2016-2393

Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows…

Fix: after 8.01.56
Fix from $1,950 2016-04-11
Shareit MEDIUM 6.1
CVE-2016-1492

The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier…

No fix yet
Fix from $1,600 2016-01-26
Shareit HIGH 8.8
CVE-2016-1491

The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it e…

Fix: after 2.5.1.1
Fix from $1,950 2016-01-26
Shareit HIGH 8.0
CVE-2016-1489

Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) ob…

Fix: after 3.0.18_ww
Fix from $1,950 2016-01-26
Switch Center HIGH 7.1
CVE-2015-7820

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8…

Fix: after 8.1.1.0
Fix from $1,950 2015-11-12
Switch Center MEDIUM 5.0
CVE-2015-7819

The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain…

Fix: after 8.1.1.0
Fix from $1,600 2015-11-12
System Update MEDIUM 6.9
CVE-2015-2234

Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files di…

Fix: after 5.06.0027
Fix from $1,600 2015-05-12
System Update HIGH 8.3
CVE-2015-2233

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which a…

Fix: after 5.06.0027
Fix from $1,950 2015-05-12
System Update HIGH 7.2
CVE-2015-2219

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privil…

Fix: after 5.06.0027
Fix from $1,950 2015-05-12
Thinkserver System Manager Baseboard Management Controller Firmware MEDIUM 5.0
CVE-2015-3323

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350…

Fix: after 118.71532.
Fix from $1,600 2015-04-16
Thinkserver Rd650 Firmware MEDIUM 5.0
CVE-2015-3322

Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passw…

Fix: after 1.25.0
Fix from $1,600 2015-04-16
Thinkpad Bluetooth With Enhanced Data Rate Software HIGH 9.3
CVE-2013-1361EPSS 6%

Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and poss…

Fix: after 6.4.0.2900
Fix from $1,950 2014-01-21
Veriface MEDIUM 6.9
CVE-2009-0655

Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.

No fix yet
Fix from $1,600 2009-02-20
Resuce And Recovery HIGH 7.2
CVE-2008-4589

Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users…

Patch available
Fix from $1,950 2008-10-15
Thinkvantage System Update MEDIUM 5.1
CVE-2008-3249

The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote at…

Fix: after 3.13.0005
Fix from $1,600 2008-07-21
Access Support MEDIUM 5.8
CVE-2007-2240

The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Au…

Mitigation only
Fix from $1,600 2007-08-15