← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
172130 14ast Firmware
130 14ikb Firmware130 15ast Firmware+169 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
1Lenovo
100Thinkpad 11e Firmware
Thinkpad 11e Yoga Gen 6 FirmwareThinkpad 13 2nd Gen Firmware+97 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
1Lenovo
1Installation Package
Jun 17, 2026
Jun 9, 2020
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.
1Lenovo
1Installation Package
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.5 MEDIUM· v3
6.9 MEDIUM· v2
A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges.
1Lenovo
3Lj4010dn Firmware
Lj6700dn FirmwareM8960dnf Firmware
Jun 17, 2026
May 28, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent...Show more
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent print jobs until the printer is rebooted.Show less
1Lenovo
3Lj4010dn Firmware
Lj6700dn FirmwareM8960dnf Firmware
Jun 17, 2026
May 28, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, causing an error to be...Show more
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, causing an error to be displayed and preventing printer from functioning until the printer is rebooted.Show less
1Lenovo
1Vantage
Jun 17, 2026
Apr 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to exec...Show more
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with elevated privileges.Show less
1Lenovo
1System Interface Foundation
Jun 17, 2026
Apr 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.
1Lenovo
1System Interface Foundation
Jun 17, 2026
Apr 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges.
1Lenovo
1System Interface Foundation
Jun 17, 2026
Apr 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with elevated privileges.
1Lenovo
1Vantage
Jun 17, 2026
Apr 14, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges.
1Lenovo
1Solution Center
Nov 21, 2024
Mar 27, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that coul...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow cross-site request forgery.Show less
1Lenovo
1Solution Center
Nov 21, 2024
Mar 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to versi...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges.Show less
1Lenovo
1Solution Center
Nov 21, 2024
Mar 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior t...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges.Show less
1Lenovo
1System Update
Nov 21, 2024
Mar 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.Show less
1Lenovo
1System Update
Nov 21, 2024
Mar 27, 2020
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allo...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges.Show less
1Lenovo
1System Update
Nov 21, 2024
Mar 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code with elevated privileges.Show less
1Lenovo
1System Update
Nov 21, 2024
Mar 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a user to execute arbitrary code with elevated privileges.Show less
1Lenovo
27B50 10 Firmware
Edge 15 FirmwareFlex 2 Pro 15 Firmware+24 more
Nov 21, 2024
Mar 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting vario...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affect...Show more
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to authorized users in the First Failure Data Capture (FFDC) service log and log files on LXCA.Show less