Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nextscale N1200 Enclosure Firmware MEDIUM 6.3
CVE-2023-2993

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited numb…

Mitigation only
Fix from $1,600 2023-06-26
Nextscale N1200 Enclosure Firmware HIGH 7.5
CVE-2023-2992

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted …

Mitigation only
Fix from $1,950 2023-06-26
Thinkpad E14 Firmware MEDIUM 6.7
CVE-2023-2290

A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute ar…

Mitigation only
Fix from $1,600 2023-06-26
Ideacentre C5 14imb05 Firmware HIGH 7.8
CVE-2022-48181

An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate…

Mitigation only
Fix from $1,950 2023-06-05
Ideacentre Aio 3 21itl7 Firmware HIGH 7.8
CVE-2022-48188

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local ac…

Mitigation only
Fix from $1,950 2023-06-05
Thinkpad Hybrid Usb C With Usb A Dock Firmware HIGH 7.8
CVE-2022-4569

A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local acces…

Fix: 1.0.35_v2+
Fix from $1,950 2023-06-05
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-0683

A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,950 2023-05-01
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-25492

A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format str…

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,950 2023-05-01
System Update HIGH 7.0
CVE-2022-4568

A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

Fix: 5.08.01.0005+
Fix from $1,950 2023-05-01
Baiying MEDIUM 6.2
CVE-2022-48186

A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure.

Fix: 1.1.4+
Fix from $1,600 2023-05-01
Smart Clock Essential With Alexa Built In Firmware HIGH 8.8
CVE-2023-0896

A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with l…

Fix: 90+
Fix from $1,950 2023-05-01
Drivers Management HIGH 7.8
CVE-2023-25496

A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code wi…

Fix: 3.1.1307.1308+
Fix from $1,950 2023-04-28
Thinkagile Hx5530 Firmware MEDIUM 5.9
CVE-2023-29056

A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be confi…

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,600 2023-04-28
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-29057

A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privile…

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,950 2023-04-28
Thinkagile Hx5530 Firmware MEDIUM 6.5
CVE-2023-29058

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through …

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,600 2023-04-28
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2022-40137

A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary c…

Mitigation only
Fix from $1,600 2023-01-30
Thinkagile Vx3331 Firmware MEDIUM 6.5
CVE-2022-34884

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem den…

Fix: 1.80_afbt20n / 3.60_tei386m+
Fix from $1,600 2023-01-30
Ideapad Y700 14isk Firmware MEDIUM 6.7
CVE-2022-3432

A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an at…

Mitigation only
Fix from $1,600 2023-01-26
Thinkbook 14 Iml Firmware HIGH 7.8
CVE-2022-1891

A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrar…

Mitigation only
Fix from $1,950 2023-01-26
100e 2nd Gen Firmware HIGH 7.8
CVE-2022-1892

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrar…

Mitigation only
Fix from $1,950 2023-01-26
Thinkbook 14 Iml Firmware HIGH 7.8
CVE-2022-1890

A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Mitigation only
Fix from $1,950 2023-01-26
D330 10igl Firmware MEDIUM 6.7
CVE-2022-3430

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify s…

Mitigation only
Fix from $1,600 2023-01-23
Safecenter MEDIUM 5.5
CVE-2022-4816

A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.

Fix: 7.2.01.0315+
Fix from $1,600 2023-01-23
Leyun HIGH 7.5
CVE-2022-1109

An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.

Fix: 6.8.21.99+
Fix from $1,950 2023-01-20
Ideacentre 510 15ikl Firmware HIGH 7.8
CVE-2019-19705

Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0…

Fix: 6.0.8923.1 / 6.0.8924.1+
Fix from $1,950 2022-12-26
Pcmanager HIGH 8.8
CVE-2022-1513

A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially craft…

Fix: 5.0.10.4191+
Fix from $1,950 2022-08-23
A1 Firmware HIGH 8.0
CVE-2021-42852

A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operat…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,950 2022-05-18
A1 Firmware HIGH 7.8
CVE-2021-42850

A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could all…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,950 2022-05-18
System Interface Foundation HIGH 7.0
CVE-2021-3969

A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to…

Fix: 1.1.20.3+
Fix from $1,950 2022-05-18
A1 Firmware MEDIUM 6.8
CVE-2021-42849

A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18