Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2018-9083 In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device … System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 HIGH 7.5 CVE-2018-16089 In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing p… System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 HIGH 7.5 CVE-2018-16090 In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command… System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 MEDIUM 6.5 CVE-2018-9084 In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can b… System Management Module Firmware 1.06+ Fix from $1,6002018-11-27 MEDIUM 6.1 CVE-2018-16096 In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input f… System Management Module Firmware 1.06+ Fix from $1,6002018-11-27 MEDIUM 5.9 CVE-2018-16095 In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails. System Management Module Firmware 1.06+ Fix from $1,6002018-11-27 HIGH 7.2 CVE-2018-9086 In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged u… Thinkserver Rd340 Firmware 60.00 / 64.00+ Fix from $1,9502018-11-16 MEDIUM 5.9 CVE-2018-9073 Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key c… Chassis Management Module Firmware 2.0.0+ Fix from $1,6002018-11-16 MEDIUM 5.3 CVE-2018-9071 Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authenticat… Chassis Management Module Firmware 2.0.0+ Fix from $1,6002018-11-16 CRITICAL 9.8 CVE-2018-9079 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DO… Storcenter Px12 450r Firmware Mitigation only Fix from $2,3002018-09-28 HIGH 8.8 CVE-2018-9078 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to uploa… Storcenter Px12 450r Firmware Mitigation only Fix from $1,9502018-09-28 HIGH 8.8 CVE-2018-9082 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated use… Storcenter Px12 450r Firmware Mitigation only Fix from $1,9502018-09-28 MEDIUM 5.9 CVE-2018-9080 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into … Storcenter Px12 450r Firmware Mitigation only Fix from $1,6002018-09-28 HIGH 8.1 CVE-2018-9075 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a comman… Lenovoemc Firmware after 4.1.402.34662 Fix from $1,9502018-09-28 HIGH 8.1 CVE-2018-9076 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command… Lenovoemc Firmware after 4.1.402.34662 Fix from $1,9502018-09-28 HIGH 8.1 CVE-2018-9077 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command… Lenovoemc Firmware after 4.1.402.34662 Fix from $1,9502018-09-28 MEDIUM 6.5 CVE-2018-9074 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application … Lenovoemc Firmware after 4.1.402.34662 Fix from $1,6002018-09-28 HIGH 8.8 CVE-2018-9064 In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials f… Xclarity Administrator 2.1.0+ Fix from $1,9502018-07-30 HIGH 8.8 CVE-2018-9066 In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional paramet… Xclarity Administrator 2.1.0+ Fix from $1,9502018-07-30 HIGH 7.5 CVE-2018-9065 In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to re… Xclarity Administrator 2.1.0+ Fix from $1,9502018-07-30 HIGH 7.5 CVE-2018-9068 The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This infor… Flex System X240 M4 Firmware 4.90+ Fix from $1,9502018-07-26 MEDIUM 6.8 CVE-2018-9062 In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. E42 80 Firmware 0zcn48ww / 2wcn40ww+ Fix from $1,6002018-07-19 HIGH 7.5 CVE-2018-9067 The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led t… Lenovo Help 6.1.2.0327+ Fix from $1,9502018-07-13 MEDIUM 6.4 CVE-2018-9070 For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a sp… Smart Assistant 12.1.82+ Fix from $1,6002018-07-13 HIGH 7.8 CVE-2018-9063 MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability wher… System Update 5.07.0072+ Fix from $1,9502018-05-04 MEDIUM 6.4 CVE-2017-3775 Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code … Flex System X240 M5 Bios 2.23 / 2.61+ Fix from $1,6002018-05-04 CRITICAL 9.8 CVE-2017-3774 A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.7… Integrated Management Module 2 4.70 / 6.60+ Fix from $2,3002018-04-19 HIGH 7.5 CVE-2017-3776 Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observi… Lenovo Help 6.1.2.0327+ Fix from $1,9502018-04-19 HIGH 7.8 CVE-2017-3762 Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data… Fingerprint Manager Pro after 8.01.86 Fix from $1,9502018-01-26 HIGH 7.0 CVE-2017-3765 In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoo… Enterprise Network Operating System 8.4.6.0+ Fix from $1,9502018-01-10