Lenovo
lenovo
406 CVEs • 4,477 products
Products (4,477)
Click to collapseToggle
Products (4,477)
Click to collapse
CVEs (406)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianLenovo+2 more38Bm Nextscale Fan Power Controller CmmDebian Linux+35 moreNov 21, 2024 Apr 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability. |
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information. |
1Lenovo 1Integrated Management Module 2 Nov 21, 2024 Apr 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in som...Show more |
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password,...Show more |
1Lenovo 1Enterprise Network Operating System Nov 21, 2024 Jan 10, 2018 N/A· v4 7.0 HIGH· v3 6.2 MEDIUM· v2 In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console,...Show more |
1Lenovo 1Xclarity Administrator May 13, 2026 Nov 30, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password informatio...Show more |
1Lenovo 3Aio E95 Firmware Thinkcentre M710s FirmwareThinkcentre M710t FirmwareMay 13, 2026 Oct 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process. |
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote co...Show more |
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attack...Show more |
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution. |
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution. |
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables. |
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations. |
1Lenovo 1Xclarity Administrator May 13, 2026 Sep 22, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operat...Show more |
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2. |
1Lenovo 1Thinkpad Usb 3.0 Ethernet Adapter Driver May 13, 2026 Aug 29, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative o...Show more |
1Lenovo 148Thinkpad 10 Ella 2 Thinkpad 10 Ella 2 BiosThinkpad 11e Beema+145 moreMay 13, 2026 Aug 18, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privil...Show more |
1Lenovo 11163 Firmware H50 30g FirmwareIdeacentre 300 20ish Firmware+108 moreMay 13, 2026 Aug 10, 2017 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileg...Show more |
1Lenovo 1Thinkpad Compact Usb Keyboard Driver May 13, 2026 Aug 10, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code...Show more |
2Ibm Lenovo251\ 1g L2 7 SlbEn2092 1gb Firmware+22 moreMay 13, 2026 Aug 9, 2017 N/A· v4 8.2 HIGH· v3 4.3 MEDIUM· v2 An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in atta...Show more |