Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

System Management Module Firmware HIGH 8.1
CVE-2018-9083

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device …

Fix: 1.06+
Fix from $1,950 2018-11-27
System Management Module Firmware HIGH 7.5
CVE-2018-16089

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing p…

Fix: 1.06+
Fix from $1,950 2018-11-27
System Management Module Firmware HIGH 7.5
CVE-2018-16090

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command…

Fix: 1.06+
Fix from $1,950 2018-11-27
System Management Module Firmware MEDIUM 6.5
CVE-2018-9084

In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can b…

Fix: 1.06+
Fix from $1,600 2018-11-27
System Management Module Firmware MEDIUM 6.1
CVE-2018-16096

In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input f…

Fix: 1.06+
Fix from $1,600 2018-11-27
System Management Module Firmware MEDIUM 5.9
CVE-2018-16095

In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.

Fix: 1.06+
Fix from $1,600 2018-11-27
Thinkserver Rd340 Firmware HIGH 7.2
CVE-2018-9086

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged u…

Fix: 60.00 / 64.00+
Fix from $1,950 2018-11-16
Chassis Management Module Firmware MEDIUM 5.9
CVE-2018-9073

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key c…

Fix: 2.0.0+
Fix from $1,600 2018-11-16
Chassis Management Module Firmware MEDIUM 5.3
CVE-2018-9071

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authenticat…

Fix: 2.0.0+
Fix from $1,600 2018-11-16
Storcenter Px12 450r Firmware CRITICAL 9.8
CVE-2018-9079

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DO…

Mitigation only
Fix from $2,300 2018-09-28
Storcenter Px12 450r Firmware HIGH 8.8
CVE-2018-9078

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to uploa…

Mitigation only
Fix from $1,950 2018-09-28
Storcenter Px12 450r Firmware HIGH 8.8
CVE-2018-9082

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated use…

Mitigation only
Fix from $1,950 2018-09-28
Storcenter Px12 450r Firmware MEDIUM 5.9
CVE-2018-9080

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into …

Mitigation only
Fix from $1,600 2018-09-28
Lenovoemc Firmware HIGH 8.1
CVE-2018-9075

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a comman…

Fix: after 4.1.402.34662
Fix from $1,950 2018-09-28
Lenovoemc Firmware HIGH 8.1
CVE-2018-9076

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command…

Fix: after 4.1.402.34662
Fix from $1,950 2018-09-28
Lenovoemc Firmware HIGH 8.1
CVE-2018-9077

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command…

Fix: after 4.1.402.34662
Fix from $1,950 2018-09-28
Lenovoemc Firmware MEDIUM 6.5
CVE-2018-9074

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application …

Fix: after 4.1.402.34662
Fix from $1,600 2018-09-28
Xclarity Administrator HIGH 8.8
CVE-2018-9064

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials f…

Fix: 2.1.0+
Fix from $1,950 2018-07-30
Xclarity Administrator HIGH 8.8
CVE-2018-9066

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional paramet…

Fix: 2.1.0+
Fix from $1,950 2018-07-30
Xclarity Administrator HIGH 7.5
CVE-2018-9065

In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to re…

Fix: 2.1.0+
Fix from $1,950 2018-07-30
Flex System X240 M4 Firmware HIGH 7.5
CVE-2018-9068

The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This infor…

Fix: 4.90+
Fix from $1,950 2018-07-26
E42 80 Firmware MEDIUM 6.8
CVE-2018-9062

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

Fix: 0zcn48ww / 2wcn40ww+
Fix from $1,600 2018-07-19
Lenovo Help HIGH 7.5
CVE-2018-9067

The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led t…

Fix: 6.1.2.0327+
Fix from $1,950 2018-07-13
Smart Assistant MEDIUM 6.4
CVE-2018-9070

For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a sp…

Fix: 12.1.82+
Fix from $1,600 2018-07-13
System Update HIGH 7.8
CVE-2018-9063

MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability wher…

Fix: 5.07.0072+
Fix from $1,950 2018-05-04
Flex System X240 M5 Bios MEDIUM 6.4
CVE-2017-3775

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code …

Fix: 2.23 / 2.61+
Fix from $1,600 2018-05-04
Integrated Management Module 2 CRITICAL 9.8
CVE-2017-3774

A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.7…

Fix: 4.70 / 6.60+
Fix from $2,300 2018-04-19
Lenovo Help HIGH 7.5
CVE-2017-3776

Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observi…

Fix: 6.1.2.0327+
Fix from $1,950 2018-04-19
Fingerprint Manager Pro HIGH 7.8
CVE-2017-3762

Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data…

Fix: after 8.01.86
Fix from $1,950 2018-01-26
Enterprise Network Operating System HIGH 7.0
CVE-2017-3765

In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoo…

Fix: 8.4.6.0+
Fix from $1,950 2018-01-10