VYPR

Thinkagile Vx 2u Firmware

by Lenovo

CVEs (3)

  • CVE-2024-2659HigApr 15, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.

  • CVE-2022-40137MedJan 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-40134MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.