← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianLenovo+2 more
38Bm Nextscale Fan Power Controller
CmmDebian Linux+35 more
Nov 21, 2024
Apr 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
1Lenovo
1Lenovo Help
Nov 21, 2024
Apr 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.
1Lenovo
1Integrated Management Module 2
Nov 21, 2024
Apr 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in som...Show more
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.Show less
1Lenovo
1Fingerprint Manager Pro
Nov 21, 2024
Jan 26, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password,...Show more
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.Show less
1Lenovo
1Enterprise Network Operating System
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.0 HIGH· v3
6.2 MEDIUM· v2
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console,...Show more
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.Show less
1Lenovo
1Xclarity Administrator
May 13, 2026
Nov 30, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password informatio...Show more
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.Show less
1Lenovo
3Aio E95 Firmware
Thinkcentre M710s FirmwareThinkcentre M710t Firmware
May 13, 2026
Oct 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.
1Lenovo
1Service Framework
May 13, 2026
Oct 17, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote co...Show more
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.Show less
1Lenovo
1Service Framework
May 13, 2026
Oct 17, 2017
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attack...Show more
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.Show less
1Lenovo
1Service Framework
May 13, 2026
Oct 17, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
1Lenovo
1Service Framework
May 13, 2026
Oct 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
1Lenovo
1System Update
May 13, 2026
Oct 3, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
1Lenovo
1Fingerprint Manager
May 13, 2026
Oct 3, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.
1Lenovo
1Xclarity Administrator
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operat...Show more
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.Show less
1Lenovo
1Xclarity Administrator
May 13, 2026
Sep 22, 2017
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.
1Lenovo
1Thinkpad Usb 3.0 Ethernet Adapter Driver
May 13, 2026
Aug 29, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative o...Show more
ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative or system level privileges.Show less
1Lenovo
148Thinkpad 10 Ella 2
Thinkpad 10 Ella 2 BiosThinkpad 11e Beema+145 more
May 13, 2026
Aug 18, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privil...Show more
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.Show less
1Lenovo
11163 Firmware
H50 30g FirmwareIdeacentre 300 20ish Firmware+108 more
May 13, 2026
Aug 10, 2017
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileg...Show more
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.Show less
1Lenovo
1Thinkpad Compact Usb Keyboard Driver
May 13, 2026
Aug 10, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code...Show more
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.Show less
2Ibm
Lenovo
251\
1g L2 7 SlbEn2092 1gb Firmware+22 more
May 13, 2026
Aug 9, 2017
N/A· v4
8.2 HIGH· v3
4.3 MEDIUM· v2
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in atta...Show more
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.Show less