Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smart Standby Driver MEDIUM 5.5
CVE-2022-1110

A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.

Fix: 4.1.50.0+
Fix from $1,600 2022-05-18
Xclarity Controller MEDIUM 5.3
CVE-2021-3956

A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting…

Fix: 1.51_tgbt24l / 2.32_psi342n+
Fix from $1,600 2022-05-18
A1 Firmware MEDIUM 5.3
CVE-2021-42848

An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrie…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18
A1 Firmware MEDIUM 5.3
CVE-2021-42851

A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18
System Interface Foundation HIGH 7.0
CVE-2021-3922

A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 th…

Fix: 1.1.20.3+
Fix from $1,950 2022-05-18
Pcmanager HIGH 7.8
CVE-2022-0192

A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.

Fix: 4.0.40.2175+
Fix from $1,950 2022-04-22
System Update HIGH 7.8
CVE-2022-0354

A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with el…

Fix: 2022-02-25+
Fix from $1,950 2022-04-22
A340 22icb Firmware MEDIUM 6.7
CVE-2021-4211

A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models…

Mitigation only
Fix from $1,600 2022-04-22
C340 14iml Firmware MEDIUM 6.7
CVE-2021-4212

A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with …

Patch available
Fix from $1,600 2022-04-22
Thinkpad 11e Firmware MEDIUM 6.7
CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some…

Mitigation only
Fix from $1,600 2022-04-22
Thinkpad X1 Fold Gen 1 Firmware MEDIUM 6.7
CVE-2022-1108

A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploite…

Mitigation only
Fix from $1,600 2022-04-22
Thin Installer MEDIUM 5.5
CVE-2022-0636

A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.

Fix: 1.3.0039+
Fix from $1,600 2022-04-22
Nextscale N1200 Enclosure Firmware CRITICAL 9.8
CVE-2021-3849

An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Mo…

Fix: 44a-3.70+
Fix from $2,300 2022-04-22
Nextscale N1200 Enclosure Firmware CRITICAL 9.8
CVE-2021-3897

An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management …

Fix: 44a-3.70+
Fix from $2,300 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3970

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with…

Mitigation only
Fix from $1,600 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3971

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included…

Mitigation only
Fix from $1,600 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3972

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deacti…

Mitigation only
Fix from $1,600 2022-04-22
Stadia Ggp 120 Firmware MEDIUM 6.7
CVE-2021-4210

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow a…

Patch available
Fix from $1,600 2022-04-22
Pcmanager MEDIUM 5.5
CVE-2021-3721

A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an attacker with local access to tr…

Fix: 4.0.10282+
Fix from $1,600 2022-04-22
Pcmanager MEDIUM 5.0
CVE-2021-3722

A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to…

Fix: 4.0.40.2175+
Fix from $1,600 2022-04-22
Antilles HIGH 8.8
CVE-2021-3840

A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execut…

Fix: 1.0.1+
Fix from $1,950 2021-11-12
Thinkpad 11e 3rd Gen Firmware MEDIUM 6.7
CVE-2021-3843

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privilege…

Fix: after 1.31
Fix from $1,600 2021-11-12
Legion Phone Pro \(l79031\)firmware MEDIUM 5.5
CVE-2021-3720

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) th…

Fix: 12.5.231 / 12.5.632+
Fix from $1,600 2021-11-12
Thinkpad X380 Yoga Firmware MEDIUM 5.5
CVE-2021-3786

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak …

Fix: 2020-10-31 / 2021-10-25+
Fix from $1,600 2021-11-12
Ideacentre C5 14mb05 Firmware MEDIUM 6.8
CVE-2021-3519

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Dev…

Mitigation only
Fix from $1,600 2021-11-12
Thinkpad X380 Yoga Firmware MEDIUM 6.7
CVE-2021-3599

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access an…

Fix: 2020-10-31 / 2021-10-25+
Fix from $1,600 2021-11-12
Thinkcentre E93 Firmware MEDIUM 6.7
CVE-2021-3719

A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCent…

Mitigation only
Fix from $1,600 2021-11-12
Smart Camera C2e Firmware CRITICAL 9.8
CVE-2021-3616

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware …

Fix: 01.03.29.16+
Fix from $2,300 2021-08-17
Drivers Management HIGH 7.8
CVE-2021-3633

A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.

Fix: 2.9.0719.1104+
Fix from $1,950 2021-08-17
Smart Camera C2e Firmware HIGH 7.2
CVE-2021-3617

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configu…

Fix: 01.03.29.16+
Fix from $1,950 2021-08-17