Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.7 CVE-2022-48189 An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to… Thinkpad E14 Firmware 1.16 / 1.18+ Fix from $1,6002023-10-30 MEDIUM 6.7 CVE-2022-4573 An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to exec… Thinkpad X1 Fold Gen 1 Firmware Mitigation only Fix from $1,6002023-10-30 HIGH 7.8 CVE-2022-3701 A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local att… System Update Plugin 1.3.1.2 / 2.0.0.213+ Fix from $1,9502023-10-27 HIGH 7.5 CVE-2022-3611 An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to … App Store App 11.8.0+ Fix from $1,9502023-10-27 HIGH 7.1 CVE-2022-3702 A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to… System Update Plugin 1.3.1.2 / 2.0.0.213+ Fix from $1,9502023-10-27 MEDIUM 6.3 CVE-2022-3700 A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could al… System Update Plugin 1.3.1.2 / 2.0.0.213+ Fix from $1,6002023-10-27 MEDIUM 6.5 CVE-2022-3429 A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, t… Gm265dn Firmware 02.06.00.04.00+ Fix from $1,6002023-10-27 HIGH 8.8 CVE-2022-34886 A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal… Gm265dn Firmware 02.06.00.04.00+ Fix from $1,9502023-10-27 MEDIUM 5.4 CVE-2022-34887 Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate wi… Gm265dn Firmware 02.06.00.04.00+ Fix from $1,6002023-10-27 HIGH 8.8 CVE-2023-4607 An authenticated XCC user can change permissions for any user through a crafted API command. Thinkagile Hx5530 Firmware Mitigation only Fix from $1,9502023-10-25 HIGH 8.1 CVE-2023-4606 An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem… Thinkagile Hx5530 Firmware Mitigation only Fix from $1,9502023-10-25 HIGH 7.2 CVE-2023-4608 An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects Thi… Thinkagile Hx5530 Firmware Mitigation only Fix from $1,9502023-10-25 HIGH 7.8 CVE-2022-3699 A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4… Diagnostics 1.3.1.2 / 2.4.1.1+ Fix from $1,9502023-10-25 MEDIUM 6.8 CVE-2022-48182 A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific c… Thinkpad T14s Gen 3 Firmware 1.30 / 1.35+ Fix from $1,6002023-10-09 MEDIUM 6.8 CVE-2022-48183 A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific c… Thinkpad T14s Gen 3 Firmware 1.30 / 1.35+ Fix from $1,6002023-10-09 MEDIUM 6.8 CVE-2022-3728 A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific c… Thinkpad T14s Gen 3 Firmware 1.30+ Fix from $1,6002023-10-09 HIGH 7.8 CVE-2022-3431 A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated … Ideapad Creator 5 16ach6 Firmware Mitigation only Fix from $1,9502023-10-09 MEDIUM 6.7 CVE-2022-3742 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil… Ideapad 1 14iau7 Firmware Mitigation only Fix from $1,6002023-08-23 MEDIUM 6.7 CVE-2022-3744 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil… Ideapad 1 14iau7 Firmware Mitigation only Fix from $1,6002023-08-23 MEDIUM 6.7 CVE-2022-3746 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil… Ideapad 1 14iau7 Firmware Mitigation only Fix from $1,6002023-08-23 HIGH 7.8 CVE-2023-3078 An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to … Universal Device Client 23.4+ Fix from $1,9502023-08-17 HIGH 7.8 CVE-2023-4030 A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure… Thinkpad T15 Gen 2 Firmware Mitigation only Fix from $1,9502023-08-17 MEDIUM 6.7 CVE-2023-4028 A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local… 13w Yoga Firmware Mitigation only Fix from $1,6002023-08-17 MEDIUM 6.7 CVE-2023-4029 A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access… K14 Type 21cu Firmware 1.10 / 1.12+ Fix from $1,6002023-08-17 MEDIUM 6.7 CVE-2023-34419 A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and e… Legion 5 Pro 16iah7h Firmware Mitigation only Fix from $1,6002023-08-17 HIGH 8.1 CVE-2023-34418 A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability… Xclarity Administrator 4.0.0+ Fix from $1,9502023-06-26 HIGH 7.5 CVE-2023-3113 An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read… Xclarity Administrator 4.0.0+ Fix from $1,9502023-06-26 HIGH 7.2 CVE-2023-34420 A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. Xclarity Administrator 4.0.0+ Fix from $1,9502023-06-26 MEDIUM 6.5 CVE-2023-34421 A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to i… Xclarity Administrator 4.0.0+ Fix from $1,6002023-06-26 MEDIUM 6.5 CVE-2023-34422 A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API… Xclarity Administrator 4.0.0+ Fix from $1,6002023-06-26