Vendor CVEs
Lenovo
All CVEs
536 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25494 | Med | 0.44 | 6.7 | 0.00 | Apr 5, 2024 | A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables. | ||
| CVE-2023-25493 | Med | 0.44 | 6.7 | 0.00 | Apr 5, 2024 | A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. | ||
| CVE-2023-5080 | Med | 0.44 | 6.8 | 0.00 | Jan 19, 2024 | A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands. | ||
| CVE-2023-45079 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | ||
| CVE-2023-45078 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | ||
| CVE-2023-45077 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | ||
| CVE-2023-45076 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | ||
| CVE-2023-45075 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | ||
| CVE-2023-43581 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43580 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43579 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43578 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43577 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43576 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43575 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43573 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43571 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-5078 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware. | ||
| CVE-2023-5075 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43570 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code. | ||
| CVE-2023-43569 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2023-43567 | Med | 0.44 | 6.7 | 0.00 | Nov 8, 2023 | A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | ||
| CVE-2022-4575 | Med | 0.44 | 6.7 | 0.00 | Oct 30, 2023 | A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot. | ||
| CVE-2022-4574 | Med | 0.44 | 6.7 | 0.00 | Oct 30, 2023 | An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2022-4573 | Med | 0.44 | 6.7 | 0.00 | Oct 30, 2023 | An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2022-48189 | Med | 0.44 | 6.7 | 0.00 | Oct 30, 2023 | An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2022-3431 | Med | 0.44 | 6.7 | 0.00 | Oct 9, 2023 | A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | ||
| CVE-2022-3746 | Med | 0.44 | 6.7 | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. | ||
| CVE-2022-3744 | Med | 0.44 | 6.7 | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. | ||
| CVE-2022-3742 | Med | 0.44 | 6.7 | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. | ||
| CVE-2023-4029 | Med | 0.44 | 6.7 | 0.00 | Aug 17, 2023 | A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2023-4028 | Med | 0.44 | 6.7 | 0.00 | Aug 17, 2023 | A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2023-34419 | Med | 0.44 | 6.7 | 0.00 | Aug 17, 2023 | A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2022-48188 | Med | 0.44 | 6.7 | 0.00 | Jun 5, 2023 | A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code. | ||
| CVE-2022-48181 | Med | 0.44 | 6.7 | 0.00 | Jun 5, 2023 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code. | ||
| CVE-2022-40137 | Med | 0.44 | 6.7 | 0.00 | Jan 30, 2023 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2022-3432 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | ||
| CVE-2022-1892 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | ||
| CVE-2022-1891 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | ||
| CVE-2022-1890 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | ||
| CVE-2022-3430 | Med | 0.44 | 6.7 | 0.00 | Jan 23, 2023 | A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | ||
| CVE-2022-4435 | Med | 0.44 | 6.7 | 0.00 | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure. | ||
| CVE-2022-4434 | Med | 0.44 | 6.7 | 0.00 | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure. | ||
| CVE-2022-4433 | Med | 0.44 | 6.7 | 0.00 | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure. | ||
| CVE-2022-4432 | Med | 0.44 | 6.7 | 0.00 | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure. | ||
| CVE-2021-42849 | Med | 0.44 | 6.8 | 0.00 | May 18, 2022 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. | ||
| CVE-2022-1108 | Med | 0.44 | 6.7 | 0.00 | Apr 22, 2022 | A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2022-1107 | Med | 0.44 | 6.7 | 0.00 | Apr 22, 2022 | During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code. | ||
| CVE-2021-4212 | Med | 0.44 | 6.7 | 0.00 | Apr 22, 2022 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2021-4211 | Med | 0.44 | 6.7 | 0.00 | Apr 22, 2022 | A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.8epss 0.00
A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.
- risk 0.44cvss 6.7epss 0.00
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
- risk 0.44cvss 6.7epss 0.00
A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
- risk 0.44cvss 6.7epss 0.00
A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
- risk 0.44cvss 6.7epss 0.00
A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
- risk 0.44cvss 6.7epss 0.00
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
- risk 0.44cvss 6.7epss 0.00
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- risk 0.44cvss 6.7epss 0.00
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
- risk 0.44cvss 6.7epss 0.00
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
- risk 0.44cvss 6.7epss 0.00
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
- risk 0.44cvss 6.7epss 0.00
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
- risk 0.44cvss 6.8epss 0.00
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Page 6 of 11