VYPR

Vendor CVEs

Lenovo

All CVEs

536 total · sorted by risk
  • CVE-2022-34888LowJan 30, 2023
    risk 0.18cvss 2.7epss 0.00

    The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.

  • CVE-2020-8352LowNov 11, 2020
    risk 0.16cvss 2.4epss 0.00

    In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.

  • CVE-2020-8341LowSep 1, 2020
    risk 0.16cvss 2.4epss 0.00

    In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for…

  • CVE-2024-23591LowFeb 16, 2024
    risk 0.13cvss 2.0epss 0.00

    ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware…

  • CVE-2012-1195Feb 18, 2012
    risk 0.08cvss epss 0.68

    Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a…

  • CVE-2012-1196Feb 18, 2012
    risk 0.07cvss epss 0.56

    Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.

  • CVE-2015-2219May 12, 2015
    risk 0.03cvss epss 0.04

    Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.

  • CVE-2013-1361Jan 21, 2014
    risk 0.01cvss epss 0.06

    Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the…

  • CVE-2026-9046HigJul 16, 2026
    risk 0.00cvss 7.0epss 0.00

    A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

  • CVE-2026-6511MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.

  • CVE-2026-14371HigJul 16, 2026
    risk 0.00cvss epss 0.01

    The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.

  • CVE-2026-13104HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.

  • CVE-2026-13103HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.

  • CVE-2026-10590MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.

  • CVE-2026-10589MedJul 16, 2026
    risk 0.00cvss 6.0epss 0.00

    A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

  • CVE-2026-10588MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

  • CVE-2026-10587MedJul 16, 2026
    risk 0.00cvss 6.0epss 0.00

    A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

  • CVE-2015-7820Nov 12, 2015
    risk 0.00cvss epss 0.01

    Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing…

  • CVE-2015-7819Nov 12, 2015
    risk 0.00cvss epss 0.01

    The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.

  • CVE-2015-7818Nov 12, 2015
    risk 0.00cvss epss 0.00

    The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a…

  • CVE-2015-7817Nov 12, 2015
    risk 0.00cvss epss 0.01

    Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing…

  • CVE-2015-3214Aug 31, 2015
    risk 0.00cvss epss 0.02

    The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

  • CVE-2015-2234May 12, 2015
    risk 0.00cvss epss 0.00

    Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.

  • CVE-2015-2233May 12, 2015
    risk 0.00cvss epss 0.00

    Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.

  • CVE-2015-3324Apr 16, 2015
    risk 0.00cvss epss 0.00

    The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof…

  • CVE-2015-3323Apr 16, 2015
    risk 0.00cvss epss 0.01

    The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.

  • CVE-2015-3322Apr 16, 2015
    risk 0.00cvss epss 0.01

    Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.

  • CVE-2015-3320Apr 16, 2015
    risk 0.00cvss epss 0.00

    Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.

  • CVE-2014-1939Mar 3, 2014
    risk 0.00cvss epss 0.01

    java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at…

  • CVE-2009-0655Feb 20, 2009
    risk 0.00cvss epss 0.00

    Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.

  • CVE-2008-4589Oct 15, 2008
    risk 0.00cvss epss 0.01

    Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.

  • CVE-2008-3249Jul 21, 2008
    risk 0.00cvss epss 0.01

    The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

  • CVE-2007-2929Aug 15, 2007
    risk 0.00cvss epss 0.03

    The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to…

  • CVE-2007-2928Aug 15, 2007
    risk 0.00cvss epss 0.05

    Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via…

  • CVE-2007-2240Aug 15, 2007
    risk 0.00cvss epss 0.03

    The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it…

  • CVE-2007-1307Mar 7, 2007
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.

Page 11 of 11