Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2018-9083
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device …
System Management Module Firmware
1.06+
HIGH 7.5
CVE-2018-16089
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing p…
System Management Module Firmware
1.06+
HIGH 7.5
CVE-2018-16090
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command…
System Management Module Firmware
1.06+
MEDIUM 6.5
CVE-2018-9084
In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can b…
System Management Module Firmware
1.06+
MEDIUM 6.1
CVE-2018-16096
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input f…
System Management Module Firmware
1.06+
MEDIUM 5.9
CVE-2018-16095
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
System Management Module Firmware
1.06+
HIGH 7.2
CVE-2018-9086
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged u…
Thinkserver Rd340 Firmware
60.00 / 64.00+
MEDIUM 5.9
CVE-2018-9073
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key c…
Chassis Management Module Firmware
2.0.0+
MEDIUM 5.3
CVE-2018-9071
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authenticat…
Chassis Management Module Firmware
2.0.0+
CRITICAL 9.8
CVE-2018-9079
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DO…
Storcenter Px12 450r Firmware
Mitigation only
HIGH 8.8
CVE-2018-9078
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to uploa…
Storcenter Px12 450r Firmware
Mitigation only
HIGH 8.8
CVE-2018-9082
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated use…
Storcenter Px12 450r Firmware
Mitigation only
MEDIUM 5.9
CVE-2018-9080
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into …
Storcenter Px12 450r Firmware
Mitigation only
HIGH 8.1
CVE-2018-9075
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a comman…
Lenovoemc Firmware
after 4.1.402.34662
HIGH 8.1
CVE-2018-9076
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command…
Lenovoemc Firmware
after 4.1.402.34662
HIGH 8.1
CVE-2018-9077
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command…
Lenovoemc Firmware
after 4.1.402.34662
MEDIUM 6.5
CVE-2018-9074
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application …
Lenovoemc Firmware
after 4.1.402.34662
HIGH 8.8
CVE-2018-9064
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials f…
Xclarity Administrator
2.1.0+
HIGH 8.8
CVE-2018-9066
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional paramet…
Xclarity Administrator
2.1.0+
HIGH 7.5
CVE-2018-9065
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to re…
Xclarity Administrator
2.1.0+
HIGH 7.5
CVE-2018-9068
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This infor…
Flex System X240 M4 Firmware
4.90+
MEDIUM 6.8
CVE-2018-9062
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
E42 80 Firmware
0zcn48ww / 2wcn40ww+
HIGH 7.5
CVE-2018-9067
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led t…
Lenovo Help
6.1.2.0327+
MEDIUM 6.4
CVE-2018-9070
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a sp…
Smart Assistant
12.1.82+
HIGH 7.8
CVE-2018-9063
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability wher…
System Update
5.07.0072+
MEDIUM 6.4
CVE-2017-3775
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code …
Flex System X240 M5 Bios
2.23 / 2.61+
CRITICAL 9.8
CVE-2017-3774
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.7…
Integrated Management Module 2
4.70 / 6.60+
HIGH 7.5
CVE-2017-3776
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observi…
Lenovo Help
6.1.2.0327+
HIGH 7.8
CVE-2017-3762
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data…
Fingerprint Manager Pro
after 8.01.86
HIGH 7.0
CVE-2017-3765
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoo…
Enterprise Network Operating System
8.4.6.0+