CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 27Ideacentre 510s 07icb Firmware Ideacentre 510s 07ick FirmwareIdeacentre 720 18apr Firmware+24 moreJun 17, 2026 Jun 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code. |
1Lenovo 147Ideacentre 3 07ada05 Firmware Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+144 moreJun 17, 2026 Jan 30, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. |
1Lenovo 136Ideacentre 3 07ada05 Firmware Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+133 moreJun 17, 2026 Jan 30, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. |
1Lenovo 325Ideacentre 3 07ada05 Firmware Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+322 moreJun 17, 2026 Jan 30, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. |
1Lenovo 32A540 24icb Firmware A540 27icb FirmwareIdeacentre 5 14imb05 Firmware+29 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitra...Show more |
1Lenovo 59Ideacentre 3 07imb05 Firmware Ideacentre 310s 08igm FirmwareIdeacentre 5 14imb05 Firmware+56 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.8 MEDIUM· v3 6.9 MEDIUM· v2 A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes. |
1Lenovo 172130 14ast Firmware 130 14ikb Firmware130 15ast Firmware+169 moreJun 17, 2026 Jun 9, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
1Lenovo 182510 15ikl Firmware 510s 08ikl FirmwareA340 22 Iwl Firmware+179 moreJun 17, 2026 Feb 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after...Show more |
2Intel Lenovo5Rapid Storage Technology Enterprise Thinkstation P520 FirmwareThinkstation P520c Firmware+2 moreJun 17, 2026 Jun 13, 2019 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access. |
1Lenovo 177330 14igm Firmware 330 15igm Firmware510 15ikl Firmware+174 moreJun 17, 2026 Apr 10, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo...Show more |
2Intel Lenovo5Rapid Storage Technology Enterprise Thinkstation P520 FirmwareThinkstation P520c Firmware+2 moreJun 17, 2026 Mar 14, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated user to potentially enable escalation of privilege via local access. L-...Show more |