Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

510 15ikl Firmware CRITICAL 9.8
CVE-2019-6188

The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W…

Mitigation only
Fix from $2,300 2019-11-12
510 15ikl Firmware MEDIUM 6.4
CVE-2019-6170

A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo Th…

Mitigation only
Fix from $1,600 2019-11-12
510 15ikl Firmware MEDIUM 6.4
CVE-2019-6172

A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo Th…

Mitigation only
Fix from $1,600 2019-11-12
System Update HIGH 7.5
CVE-2019-6175

A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written…

Fix: 5.07.0088+
Fix from $1,950 2019-09-26
Cp Storage Block Firmware HIGH 7.5
CVE-2019-6161

An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmwa…

Fix: 1908.m+
Fix from $1,950 2019-09-26
Xclarity Administrator HIGH 7.5
CVE-2019-6179

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity I…

Fix: 2.5.0 / 6.1.0+
Fix from $1,950 2019-09-03
Xclarity Administrator MEDIUM 6.1
CVE-2019-6181

A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a …

Fix: 2.5.0+
Fix from $1,600 2019-09-03
Legion Y520t Z370 Firmware MEDIUM 6.5
CVE-2019-10724

There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at…

Fix: 6.0.1.8642+
Fix from $1,600 2019-08-29
Solution Center CRITICAL 9.8
CVE-2019-6177

A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standa…

Mitigation only
Fix from $2,300 2019-08-21
Px12 350r Firmware MEDIUM 5.3
CVE-2019-6178

An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through t…

Mitigation only
Fix from $1,600 2019-08-19
Yoga 700 11isk Firmware HIGH 7.8
CVE-2019-6165

A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended s…

Mitigation only
Fix from $1,950 2019-08-19
20f1 Firmware MEDIUM 6.8
CVE-2019-6171

A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical ac…

Mitigation only
Fix from $1,600 2019-08-19
Bladecenter Hs22 Firmware MEDIUM 6.1
CVE-2019-6159

A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Mana…

Mitigation only
Fix from $1,600 2019-08-19
Px12 350r Firmware HIGH 7.5
CVE-2019-6160

A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the AP…

Fix: 2.1.50.30227 / 3.2.16.30221+
Fix from $1,950 2019-07-16
Service Bridge CRITICAL 9.8
CVE-2019-6167

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

Fix: 4.1.0.1+
Fix from $2,300 2019-06-26
Service Bridge CRITICAL 9.8
CVE-2019-6168

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

Fix: 4.1.0.1+
Fix from $2,300 2019-06-26
Service Bridge HIGH 8.8
CVE-2019-6166

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.

Fix: 4.1.0.1+
Fix from $1,950 2019-06-26
System Update HIGH 7.5
CVE-2019-6163

A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to n…

Fix: 5.07.0084+
Fix from $1,950 2019-06-26
Service Bridge HIGH 7.5
CVE-2019-6169

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.

Fix: 4.1.0.1+
Fix from $1,950 2019-06-26
Xclarity Administrator MEDIUM 5.9
CVE-2019-6158

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear tex…

Fix: 2.4.0+
Fix from $1,600 2019-05-03
Flex System X240 M4 Firmware HIGH 7.5
CVE-2019-6157

In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web serv…

Fix: 5.30+
Fix from $1,950 2019-04-22
Bootable Usb HIGH 7.8
CVE-2019-6154

A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local ac…

Patch available
Fix from $1,950 2019-04-10
Dynamic Power Reduction MEDIUM 6.7
CVE-2019-6149

An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious …

Fix: 2.2.2.0+
Fix from $1,600 2019-03-18
Synaptics Thinkpad Ultranav Driver HIGH 7.8
CVE-2018-16098

In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could all…

Patch available
Fix from $1,950 2019-01-24
Xclarity Integrator MEDIUM 6.5
CVE-2018-16093

In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload…

Fix: 5.5+
Fix from $1,600 2018-11-30
Xclarity Integrator MEDIUM 6.5
CVE-2018-16097

LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system …

Fix: 3.5 / 5.5+
Fix from $1,600 2018-11-30
Xclarity Integrator MEDIUM 6.5
CVE-2018-9072

In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file…

Fix: 5.5+
Fix from $1,600 2018-11-30
System Management Module Firmware HIGH 8.1
CVE-2018-16091

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.

Fix: 1.06+
Fix from $1,950 2018-11-27
System Management Module Firmware HIGH 8.1
CVE-2018-16092

In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive informati…

Fix: 1.06+
Fix from $1,950 2018-11-27
System Management Module Firmware HIGH 8.1
CVE-2018-16094

In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflo…

Fix: 1.06+
Fix from $1,950 2018-11-27