← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Xclarity Controller
Jun 17, 2026
Feb 14, 2020
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to hig...Show more
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Feb 14, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Feb 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, licens...Show more
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.Show less
1Lenovo
182510 15ikl Firmware
510s 08ikl FirmwareA340 22 Iwl Firmware+179 more
Jun 17, 2026
Feb 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after...Show more
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.Show less
1Lenovo
2Ez Media & Backup Center Ix2 Dl Firmware
Ez Media & Backup Center Ix2 Firmware
Jun 17, 2026
Feb 14, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Feb 14, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to...Show more
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.Show less
1Lenovo
1Power Management Driver
Jun 17, 2026
Dec 10, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.
1Lenovo
1Energy Management
Jun 17, 2026
Dec 10, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a...Show more
A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not affected.Show less
1Lenovo
1Paper
Jun 17, 2026
Nov 20, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.
1Lenovo
1System Interface Foundation
Jun 17, 2026
Nov 20, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.
1Lenovo
1Xclarity Controller
Jun 17, 2026
Nov 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informationa...Show more
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.Show less
1Lenovo
1System Interface Foundation
Jun 17, 2026
Nov 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.
1Lenovo
1Customer Engagement Service
Jun 17, 2026
Nov 20, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.
1Lenovo
1Thinkpad Usb C Dock Firmware
Jun 17, 2026
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
1Lenovo
392130 14ikb Firmware
130 15ikb Firmware330 14ikb Firmware+389 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
1Lenovo
392130 14ikb Firmware
130 15ikb Firmware330 14ikb Firmware+389 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
1Lenovo
392130 14ikb Firmware
130 15ikb Firmware330 14ikb Firmware+389 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
1Lenovo
1System Update
Jun 17, 2026
Sep 26, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations.
1Lenovo
1Cp Storage Block Firmware
Jun 17, 2026
Sep 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to b...Show more
An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Sep 3, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that coul...Show more
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.Show less