← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Hp
Lenovo
68310s 14isk Firmware
320 15ikbra Firmware320 15ikbrn Firmware+65 more
Jun 17, 2026
Oct 2, 2018
N/A· v4
5.9 MEDIUM· v3
7.0 HIGH· v2
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the co...Show more
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Jun 17, 2026
Sep 28, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's accountShow less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Jun 17, 2026
Sep 28, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Jun 17, 2026
Sep 28, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cook...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Jun 17, 2026
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags an...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.Show less
1Lenovo
20Ez Media & Backup Center Firmware
Ix2 FirmwareIx4 300d Firmware+17 more
Jun 17, 2026
Sep 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the dev...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.Show less
1Lenovo
1Lenovoemc Firmware
Jun 17, 2026
Sep 28, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name p...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.Show less
1Lenovo
1Lenovoemc Firmware
Jun 17, 2026
Sep 28, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.Show less
1Lenovo
1Lenovoemc Firmware
Jun 17, 2026
Sep 28, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:passwo...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.Show less
1Lenovo
1Lenovoemc Firmware
Jun 17, 2026
Sep 28, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files an...Show more
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.Show less
2Intel
Lenovo
32Core I3
Core I5Core I7+29 more
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.6 HIGH· v3
4.6 MEDIUM· v2
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor...Show more
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Jul 30, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command...Show more
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Jul 30, 2018
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names a...Show more
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Jul 30, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
2Ibm
Lenovo
42Bladecenter Hs22 Firmware
Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 more
Jun 17, 2026
Jul 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on...Show more
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.Show less
1Lenovo
39E42 80 Firmware
E42 80 Isk FirmwareE52 80 Firmware+36 more
Jun 17, 2026
Jul 19, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
1Lenovo
1Smart Assistant
Jun 17, 2026
Jul 13, 2018
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web servic...Show more
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.Show less
1Lenovo
1Lenovo Help
Jun 17, 2026
Jul 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.
1Lenovo
1System Update
Jun 17, 2026
May 4, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the p...Show more
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional privilege is granted to the attacker beyond what is already possessed to run MapDrv.Show less
1Lenovo
11Flex System X240 M5 Bios
Flex System X280 X6 BiosFlex System X480 X6 Bios+8 more
Nov 21, 2024
May 4, 2018
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the...Show more
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.Show less