VYPR

Vendor CVEs

Lenovo

All CVEs

536 total · sorted by risk
  • CVE-2021-4210MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3972MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.03

    A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2021-3971MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.01

    A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM…

  • CVE-2021-3970MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.01

    A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3843MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3719MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3599MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-3453MedJul 16, 2021
    risk 0.44cvss 6.8epss 0.00

    Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

  • CVE-2021-3452MedJul 16, 2021
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2020-8353MedNov 11, 2020
    risk 0.44cvss 6.7epss 0.01

    Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

  • CVE-2020-8337MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.00

    An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code.

  • CVE-2019-6196MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.00

    A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.

  • CVE-2019-6173MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.00

    A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges.

  • CVE-2019-6171MedAug 19, 2019
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

  • CVE-2019-6149MedMar 18, 2019
    risk 0.44cvss 6.7epss 0.00

    An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.

  • CVE-2018-9062MedJul 19, 2018
    risk 0.44cvss 6.8epss 0.01

    In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

  • CVE-2015-3321MedOct 3, 2017
    risk 0.44cvss 6.7epss 0.00

    Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.

  • CVE-2017-3763MedSep 22, 2017
    risk 0.44cvss 6.7epss 0.00

    An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.

  • CVE-2017-3753MedAug 10, 2017
    risk 0.44cvss 6.8epss 0.01

    A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run…

  • CVE-2017-3754MedJul 17, 2017
    risk 0.44cvss 6.7epss 0.00

    Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

  • CVE-2026-4135MedApr 15, 2026
    risk 0.43cvss 6.6epss 0.00

    During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

  • CVE-2025-8421MedNov 12, 2025
    risk 0.43cvss 6.6epss 0.00

    An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.

  • CVE-2021-3615MedAug 17, 2021
    risk 0.43cvss 6.6epss 0.00

    A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card. This vulnerability is the same as CNVD-2021-45262.

  • CVE-2026-0421MedJan 14, 2026
    risk 0.42cvss 6.5epss 0.00

    A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is…

  • CVE-2024-6004MedAug 16, 2024
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted.

  • CVE-2024-5210MedAug 16, 2024
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted.

  • CVE-2024-5209MedAug 16, 2024
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted.

  • CVE-2024-4782MedAug 16, 2024
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs.

  • CVE-2024-4781MedAug 16, 2024
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted.

  • CVE-2024-23594MedApr 15, 2024
    risk 0.42cvss 6.4epss 0.00

    A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code.

  • CVE-2023-4605MedApr 5, 2024
    risk 0.42cvss 6.5epss 0.00

    A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

  • CVE-2023-6540MedJan 3, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosure of sensitive information.

  • CVE-2022-3429MedOct 27, 2023
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.

  • CVE-2023-34422MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.

  • CVE-2023-34421MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.

  • CVE-2023-2290MedJun 26, 2023
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-29058MedApr 28, 2023
    risk 0.42cvss 6.4epss 0.00

    A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

  • CVE-2021-3519MedNov 12, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

  • CVE-2021-3614MedJul 16, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.

  • CVE-2020-8354MedNov 11, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.

  • CVE-2020-8332MedOct 14, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.

  • CVE-2020-8333MedSep 24, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution

  • CVE-2020-8336MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.

  • CVE-2020-8323MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.

  • CVE-2020-8322MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

  • CVE-2020-8321MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.

  • CVE-2020-8320MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

  • CVE-2019-6187MedNov 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being…

  • CVE-2019-6172MedNov 12, 2019
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.

  • CVE-2019-6170MedNov 12, 2019
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.

Page 7 of 11