VYPR

Vendor CVEs

Lenovo

All CVEs

536 total · sorted by risk
  • CVE-2023-25494MedApr 5, 2024
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-25493MedApr 5, 2024
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.

  • CVE-2023-5080MedJan 19, 2024
    risk 0.44cvss 6.8epss 0.00

    A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.

  • CVE-2023-45079MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45078MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45077MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45076MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-45075MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

  • CVE-2023-43581MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43580MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43579MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43578MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43577MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43576MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43575MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43573MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43571MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-5078MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

  • CVE-2023-5075MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2023-43570MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

  • CVE-2023-43569MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. 

  • CVE-2023-43567MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2022-4575MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

  • CVE-2022-4574MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  

  • CVE-2022-4573MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-48189MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-3431MedOct 9, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2022-3746MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.

  • CVE-2022-3744MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.

  • CVE-2022-3742MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.

  • CVE-2023-4029MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-4028MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-34419MedAug 17, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-48188MedJun 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

  • CVE-2022-48181MedJun 5, 2023
    risk 0.44cvss 6.7epss 0.00

    An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.

  • CVE-2022-40137MedJan 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-3432MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2022-1892MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

  • CVE-2022-1891MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

  • CVE-2022-1890MedJan 26, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

  • CVE-2022-3430MedJan 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2022-4435MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4434MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4433MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4432MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2021-42849MedMay 18, 2022
    risk 0.44cvss 6.8epss 0.00

    A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.

  • CVE-2022-1108MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-1107MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

  • CVE-2021-4212MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-4211MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Page 6 of 11