← Back

Lenovo

lenovo

395 CVEs • 4,474 products

Products (4,474)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (395)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1System Management Module Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.
1Lenovo
1System Management Module Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow fil...Show more
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.Show less
1Lenovo
1System Management Module Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.
1Lenovo
1System Management Module Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.
1Lenovo
1System Management Module Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
1Lenovo
4Thinkserver Rd340 Firmware
Thinkserver Rd440 FirmwareThinkserver Rd640 Firmware+1 more
Nov 21, 2024
Nov 16, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can onl...Show more
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.Show less
2Ibm
Lenovo
29Bladecenter Hs23 Firmware
Bladecenter Hs23e FirmwareFlex System X220 M4 Firmware+26 more
Nov 21, 2024
Nov 16, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing...Show more
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.Show less
1Lenovo
1Chassis Management Module Firmware
Nov 21, 2024
Nov 16, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt...Show more
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.Show less
1Lenovo
1Chassis Management Module Firmware
Nov 21, 2024
Nov 16, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths...Show more
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.Show less
2Hp
Lenovo
68310s 14isk Firmware
320 15ikbra Firmware320 15ikbrn Firmware+65 more
Nov 21, 2024
Oct 2, 2018
N/A· v4
5.9 MEDIUM· v3
7.0 HIGH· v2
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the co...Show more
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Nov 21, 2024
Sep 28, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's accountShow less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Nov 21, 2024
Sep 28, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Nov 21, 2024
Sep 28, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cook...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags an...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Nov 21, 2024
Sep 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the dev...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.Show less
1Lenovo
1Lenovoemc Firmware
Nov 21, 2024
Sep 28, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name p...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.Show less
1Lenovo
1Lenovoemc Firmware
Nov 21, 2024
Sep 28, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.Show less
1Lenovo
1Lenovoemc Firmware
Nov 21, 2024
Sep 28, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:passwo...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.Show less
1Lenovo
1Lenovoemc Firmware
Nov 21, 2024
Sep 28, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files an...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.Show less
2Intel
Lenovo
32Core I3
Core I5Core I7+29 more
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.6 HIGH· v3
4.6 MEDIUM· v2
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor...Show more
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.Show less