← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Cloud Networking Operating System
Jun 17, 2026
Oct 14, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default...Show more
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL.Show less
1Lenovo
1Hardware Scan
Jun 17, 2026
Oct 14, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege.
1Lenovo
1Diagnostics
Jun 17, 2026
Oct 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.
1Lenovo
18Bladecenter Hs23 Firmware
Bladecenter Hs23e FirmwareCompute Node X440 Firmware+15 more
Jun 17, 2026
Oct 14, 2020
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not af...Show more
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.Show less
1Lenovo
1Enterprise Network Disk
Jun 17, 2026
Sep 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser sess...Show more
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.Show less
1Lenovo
1Enterprise Network Disk
Jun 17, 2026
Sep 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafte...Show more
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing.Show less
1Lenovo
2763 Firmware
H50 30g FirmwareM4500 Firmware+24 more
Jun 17, 2026
Sep 24, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
1Lenovo
1System Interface Foundation
Jun 17, 2026
Sep 15, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locati...Show more
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.Show less
1Lenovo
1System Update
Jun 17, 2026
Sep 15, 2020
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.
1Lenovo
1Integrated Management Module 2
Jun 17, 2026
Sep 15, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface d...Show more
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in the user's web browser if the user is convinced to visit a crafted URL, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the crafted URL. Impact is limited to the normal access restrictions and permissions of the user clicking the crafted URL, and subject to the user being able to connect to and already being authenticated to IMM2 or other systems. The JavaScript code is not executed on IMM2 itself.Show less
1Lenovo
10Thinkpad T490 (20nx) Firmware
Thinkpad T490 (20qx) FirmwareThinkpad T490 (20rx) Firmware+7 more
Jun 17, 2026
Sep 1, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After...Show more
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.Show less
1Lenovo
8Thinkpad A275 Firmware
Thinkpad A285 FirmwareThinkpad A475 Firmware+5 more
Jun 17, 2026
Sep 1, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w...Show more
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.Show less
1Lenovo
1Drivers Management
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
1Lenovo
1Drivers Management
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
3Hp
LenovoSynaptics
112Envy 13t Ah100 Firmware
Envy 13t Aq100 FirmwareEnvy 17t Bw000 Firmware+109 more
Jun 17, 2026
Jul 22, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise c...Show more
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.Show less
3Hp
LenovoSynaptics
133Elite Slice Firmware
Elite X2 1012 G2 FirmwareElite X2 1013 G3 Firmware+130 more
Jun 17, 2026
Jul 22, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the...Show more
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.Show less
1Lenovo
38Thinkpad E14 Firmware
Thinkpad E15 FirmwareThinkpad E490 Firmware+35 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
1Lenovo
7Thinkpad A275 Firmware
Thinkpad A285 FirmwareThinkpad A475 Firmware+4 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.
1Lenovo
17214iwl Firmware
330 14ast Firmware330 15ast Firmware+169 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
1Lenovo
5114iwl Firmware
330 14ast Firmware330 15ast Firmware+48 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.