Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thinkpad E14 Firmware MEDIUM 6.7
CVE-2022-48189

An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to…

Fix: 1.16 / 1.18+
Fix from $1,600 2023-10-30
Thinkpad X1 Fold Gen 1 Firmware MEDIUM 6.7
CVE-2022-4573

An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to exec…

Mitigation only
Fix from $1,600 2023-10-30
System Update Plugin HIGH 7.8
CVE-2022-3701

A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local att…

Fix: 1.3.1.2 / 2.0.0.213+
Fix from $1,950 2023-10-27
App Store App HIGH 7.5
CVE-2022-3611

An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to …

Fix: 11.8.0+
Fix from $1,950 2023-10-27
System Update Plugin HIGH 7.1
CVE-2022-3702

A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to…

Fix: 1.3.1.2 / 2.0.0.213+
Fix from $1,950 2023-10-27
System Update Plugin MEDIUM 6.3
CVE-2022-3700

A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could al…

Fix: 1.3.1.2 / 2.0.0.213+
Fix from $1,600 2023-10-27
Gm265dn Firmware MEDIUM 6.5
CVE-2022-3429

A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, t…

Fix: 02.06.00.04.00+
Fix from $1,600 2023-10-27
Gm265dn Firmware HIGH 8.8
CVE-2022-34886

A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal…

Fix: 02.06.00.04.00+
Fix from $1,950 2023-10-27
Gm265dn Firmware MEDIUM 5.4
CVE-2022-34887

Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate wi…

Fix: 02.06.00.04.00+
Fix from $1,600 2023-10-27
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-4607

An authenticated XCC user can change permissions for any user through a crafted API command.

Mitigation only
Fix from $1,950 2023-10-25
Thinkagile Hx5530 Firmware HIGH 8.1
CVE-2023-4606

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem…

Mitigation only
Fix from $1,950 2023-10-25
Thinkagile Hx5530 Firmware HIGH 7.2
CVE-2023-4608

An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects Thi…

Mitigation only
Fix from $1,950 2023-10-25
Diagnostics HIGH 7.8
CVE-2022-3699

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4…

Fix: 1.3.1.2 / 2.4.1.1+
Fix from $1,950 2023-10-25
Thinkpad T14s Gen 3 Firmware MEDIUM 6.8
CVE-2022-48182

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific c…

Fix: 1.30 / 1.35+
Fix from $1,600 2023-10-09
Thinkpad T14s Gen 3 Firmware MEDIUM 6.8
CVE-2022-48183

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific c…

Fix: 1.30 / 1.35+
Fix from $1,600 2023-10-09
Thinkpad T14s Gen 3 Firmware MEDIUM 6.8
CVE-2022-3728

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific c…

Fix: 1.30+
Fix from $1,600 2023-10-09
Ideapad Creator 5 16ach6 Firmware HIGH 7.8
CVE-2022-3431

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated …

Mitigation only
Fix from $1,950 2023-10-09
Ideapad 1 14iau7 Firmware MEDIUM 6.7
CVE-2022-3742

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil…

Mitigation only
Fix from $1,600 2023-08-23
Ideapad 1 14iau7 Firmware MEDIUM 6.7
CVE-2022-3744

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil…

Mitigation only
Fix from $1,600 2023-08-23
Ideapad 1 14iau7 Firmware MEDIUM 6.7
CVE-2022-3746

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil…

Mitigation only
Fix from $1,600 2023-08-23
Universal Device Client HIGH 7.8
CVE-2023-3078

An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to …

Fix: 23.4+
Fix from $1,950 2023-08-17
Thinkpad T15 Gen 2 Firmware HIGH 7.8
CVE-2023-4030

A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure…

Mitigation only
Fix from $1,950 2023-08-17
13w Yoga Firmware MEDIUM 6.7
CVE-2023-4028

A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local…

Mitigation only
Fix from $1,600 2023-08-17
K14 Type 21cu Firmware MEDIUM 6.7
CVE-2023-4029

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access…

Fix: 1.10 / 1.12+
Fix from $1,600 2023-08-17
Legion 5 Pro 16iah7h Firmware MEDIUM 6.7
CVE-2023-34419

A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and e…

Mitigation only
Fix from $1,600 2023-08-17
Xclarity Administrator HIGH 8.1
CVE-2023-34418

A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability…

Fix: 4.0.0+
Fix from $1,950 2023-06-26
Xclarity Administrator HIGH 7.5
CVE-2023-3113

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read…

Fix: 4.0.0+
Fix from $1,950 2023-06-26
Xclarity Administrator HIGH 7.2
CVE-2023-34420

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.

Fix: 4.0.0+
Fix from $1,950 2023-06-26
Xclarity Administrator MEDIUM 6.5
CVE-2023-34421

A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to i…

Fix: 4.0.0+
Fix from $1,600 2023-06-26
Xclarity Administrator MEDIUM 6.5
CVE-2023-34422

A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API…

Fix: 4.0.0+
Fix from $1,600 2023-06-26