← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Bios
May 13, 2026
Jul 17, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with...Show more
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.Show less
1Lenovo
1Connect2
May 13, 2026
Jul 17, 2017
N/A· v4
4.8 MEDIUM· v3
2.3 LOW· v2
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection...Show more
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents could connect to the Connect2 hotspot and see the contents of files while they are being transferred between the two systems.Show less
1Lenovo
1Nerve Center
May 13, 2026
Jun 29, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alt...Show more
Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.Show less
1Lenovo
1Xclarity Administrator
May 13, 2026
Jun 20, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's...Show more
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.Show less
2Ibm
Lenovo
2Integrated Management Module Firmware
Integrated Management Module Firmware
May 13, 2026
Jun 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote com...Show more
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.Show less
1Lenovo
3Advanced Settings Utility
Toolscenter Dynamic System AnalysisUpdatexpress System Pack Installer
May 13, 2026
Jun 20, 2017
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System...Show more
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.Show less
1Lenovo
1Mouse Suite
May 13, 2026
Jun 13, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.
1Lenovo
1Power Management
May 13, 2026
Jun 4, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.
1Lenovo
1Active Protection System
May 13, 2026
Jun 4, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to...Show more
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.Show less
1Lenovo
1Lenovo Service Bridge
May 13, 2026
Jun 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
1Lenovo
1Lenovo Service Bridge
May 13, 2026
Jun 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
1Lenovo
1Lenovo Service Bridge
May 13, 2026
Jun 4, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.
1Lenovo
1Lenovo Service Bridge
May 13, 2026
Jun 4, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.
1Lenovo
1Solution Center
May 13, 2026
May 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.
1Lenovo
1Lenovo System Update
May 13, 2026
Apr 24, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI...Show more
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."Show less
1Lenovo
1Lenovo System Update
May 13, 2026
Apr 24, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that...Show more
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."Show less
1Lenovo
1Updates
May 13, 2026
Apr 10, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
1Lenovo
1Customer Care Software Development Kit
May 13, 2026
Apr 10, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.
7Apache
ArubanetworksHp+4 more
9Clearpass Policy Manager
Oncommand BalanceServer Automation+6 more
Apr 21, 2026
Mar 11, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex...Show more
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.Show less
1Lenovo
1Thinkserver Firmware
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77.