← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
3Smart Camera C2e Firmware
Smart Camera X3 FirmwareSmart Camera X5 Firmware
Jun 17, 2026
Aug 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNV...Show more
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.Show less
1Lenovo
3Smart Camera C2e Firmware
Smart Camera X3 FirmwareSmart Camera X5 Firmware
Jun 17, 2026
Aug 17, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card. This vulnerability is the same as CNVD-2021-45262.
1Lenovo
21100e 2nd Gen Firmware
300e 2nd Gen FirmwareIdeapad 1 11ada05 Firmware+18 more
Jun 17, 2026
Jul 16, 2021
N/A· v4
6.8 MEDIUM· v3
4.4 MEDIUM· v2
A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.
1Lenovo
1Pcmanager
Jun 17, 2026
Jul 16, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.
1Lenovo
21730s 13iml Firmware
Ideacentre Aio 5 24imb05 FirmwareIdeacentre Aio 5 74imb05 Firmware+18 more
Jun 17, 2026
Jul 16, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
1Lenovo
1Bios
Jun 17, 2026
Jul 16, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1Lenovo
1Pcmanager
Jun 17, 2026
Apr 27, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.
1Lenovo
1Pcmanager
Jun 17, 2026
Apr 27, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.
1Lenovo
1Xclarity Controller
Jun 17, 2026
Apr 13, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is...Show more
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal log buffer for less than 10 minutes before being overwritten. Generating an FFDC service log will include the log buffer contents, including the backup/restore password if present. The FFDC service log is only generated when requested by a privileged XCC user and it is only accessible to the privileged XCC user that requested the file. The backup/restore password is not captured if the backup/restore is initiated directly from XCC.Show less
1Lenovo
1Power Management Driver
Jun 17, 2026
Apr 13, 2021
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.
1Lenovo
1Power Management Driver
Jun 17, 2026
Apr 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.
1Lenovo
1Xclarity Orchestrator
Jun 17, 2026
Mar 9, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log f...Show more
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Mar 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.
1Lenovo
1Xclarity Orchestrator
Jun 17, 2026
Mar 9, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected lo...Show more
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Feb 10, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captur...Show more
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating. The service log is only generated when requested by a privileged LXCA user and it is only accessible to the privileged LXCA user that requested the file and is then deleted.Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Nov 30, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
1Lenovo
1Notebook Firmware
Jun 17, 2026
Nov 11, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.
1Lenovo
14Thinkcentre M80s Firmware
Thinkcentre M80t FirmwareThinkcentre M90s Firmware+11 more
Jun 17, 2026
Nov 11, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access...Show more
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.Show less
1Lenovo
16Qitian 4500 Firmware
Qitian B4550 FirmwareQitian M4550 Firmware+13 more
Jun 17, 2026
Nov 11, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
1Lenovo
1Thinkpad Stack Wireless Router Firmware
Jun 17, 2026
Oct 14, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege.