VYPR

Thinkpad

by Lenovo

CVEs (29)

  • CVE-2023-4030HigAug 17, 2023
    risk 0.55cvss 8.4epss 0.00

    A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.

  • CVE-2024-12673HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V…

  • CVE-2017-3756HigAug 18, 2017
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.

  • CVE-2018-12169HigSep 21, 2018
    risk 0.49cvss 7.6epss 0.01

    Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to…

  • CVE-2025-10238MedJun 10, 2026
    risk 0.44cvss 6.7epss 0.00

    During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).

  • CVE-2025-10237MedJun 10, 2026
    risk 0.44cvss 6.7epss 0.00

    During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.

  • CVE-2022-4575MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

  • CVE-2022-48189MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-4029MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-48181MedJun 5, 2023
    risk 0.44cvss 6.7epss 0.00

    An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.

  • CVE-2022-4435MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4434MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4433MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4432MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-1107MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

  • CVE-2021-3843MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3599MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3453MedJul 16, 2021
    risk 0.44cvss 6.8epss 0.00

    Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

  • CVE-2021-3452MedJul 16, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2018-9062MedJul 19, 2018
    risk 0.44cvss 6.8epss 0.01

    In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

Page 1 of 2