Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smart Camera C2e Firmware MEDIUM 6.8
CVE-2021-3615

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card…

Fix: 01.03.29.16+
Fix from $1,600 2021-08-17
Pcmanager HIGH 7.8
CVE-2021-3550

A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.

Fix: 3.0.500.5102+
Fix from $1,950 2021-07-16
Ideapad 1 11ada05 Firmware MEDIUM 6.8
CVE-2021-3614

A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain co…

No fix yet
Fix from $1,600 2021-07-16
Bios MEDIUM 6.7
CVE-2021-3452

A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated p…

Mitigation only
Fix from $1,600 2021-07-16
Pcmanager HIGH 7.8
CVE-2021-3464

A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.

Fix: 3.0.400.3252+
Fix from $1,950 2021-04-27
Pcmanager MEDIUM 5.5
CVE-2021-3451

A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written…

Fix: 3.0.400.3252+
Fix from $1,600 2021-04-27
Power Management Driver HIGH 7.8
CVE-2021-3462

A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized acc…

Fix: 1.67.17.54+
Fix from $1,950 2021-04-13
Pcmanager MEDIUM 5.5
CVE-2020-8357

A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written…

Fix: 3.0.200.2042+
Fix from $1,600 2021-03-09
Pcmanager HIGH 7.8
CVE-2020-8351

A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute …

Fix: 3.0.50.9162+
Fix from $1,950 2020-11-30
Thinkcentre M80t Firmware MEDIUM 6.7
CVE-2020-8353

Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel…

Fix: 2020-08-10+
Fix from $1,600 2020-11-11
Notebook Firmware MEDIUM 6.7
CVE-2020-8354

A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code …

Mitigation only
Fix from $1,600 2020-11-11
Cloud Networking Operating System CRITICAL 9.8
CVE-2020-8349

An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ option…

Fix: 10.10.6.0+
Fix from $2,300 2020-10-14
Thinkpad Stack Wireless Router Firmware HIGH 8.8
CVE-2020-8350

An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of …

Fix: after 1.1.3.4
Fix from $1,950 2020-10-14
Diagnostics HIGH 7.8
CVE-2020-8338

A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code …

Fix: 4.35.4+
Fix from $1,950 2020-10-14
Hardware Scan HIGH 7.8
CVE-2020-8345

A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.1…

Fix: 1.0.46.11+
Fix from $1,950 2020-10-14
Bladecenter Hs23 Firmware MEDIUM 6.4
CVE-2020-8332

A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may al…

Mitigation only
Fix from $1,600 2020-10-14
Enterprise Network Disk MEDIUM 6.1
CVE-2020-8347

A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could…

Mitigation only
Fix from $1,600 2020-09-24
Enterprise Network Disk MEDIUM 6.1
CVE-2020-8348

A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could …

Mitigation only
Fix from $1,600 2020-09-24
63 Firmware HIGH 7.8
CVE-2020-8333

A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary …

Patch available
Fix from $1,950 2020-09-24
System Update HIGH 7.0
CVE-2020-8342

A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.

Fix: 5.07.0106+
Fix from $1,950 2020-09-15
Integrated Management Module 2 MEDIUM 6.1
CVE-2020-8340

A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to versi…

Fix: 5.60 / 5.61+
Fix from $1,600 2020-09-15
System Interface Foundation MEDIUM 5.5
CVE-2020-8346

A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 th…

Fix: 1.1.19.5+
Fix from $1,600 2020-09-15
Thinkpad A275 Firmware MEDIUM 6.8
CVE-2020-8335

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495…

Fix: 2020-08-30+
Fix from $1,600 2020-09-01
Drivers Management HIGH 7.8
CVE-2020-8317

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to ex…

Fix: 2.7.1128.1046+
Fix from $1,950 2020-07-24
Drivers Management HIGH 7.8
CVE-2020-8326

An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated use…

Fix: 2.7.1128.1046+
Fix from $1,950 2020-07-24
Thinkpad 11e Yoga Gen 6 Firmware MEDIUM 6.8
CVE-2020-8320

An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

Fix: 2020-07-10+
Fix from $1,600 2020-06-09
Thinkpad T495s Firmware MEDIUM 6.8
CVE-2020-8334

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized a…

Mitigation only
Fix from $1,600 2020-06-09
Thinkpad E14 Firmware MEDIUM 6.8
CVE-2020-8336

Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.

Fix: 2020-07-10+
Fix from $1,600 2020-06-09
130 14ast Firmware MEDIUM 6.7
CVE-2020-8321

A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models…

Mitigation only
Fix from $1,600 2020-06-09
330 14ast Firmware MEDIUM 6.7
CVE-2020-8322

A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitr…

Mitigation only
Fix from $1,600 2020-06-09