Lenovo
lenovo
406 CVEs • 4,477 products
Products (4,477)
Click to collapseToggle
Products (4,477)
Click to collapse
CVEs (406)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 3Hardware Scan Addin Hardware Scan PluginSystem Update PluginJun 17, 2026 Oct 27, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files. |
An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications. |
1Lenovo 3G263dns Firmware Gm265dn FirmwareGm266dns FirmwareJun 17, 2026 Oct 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents...Show more |
1Lenovo 3G263dns Firmware Gm265dn FirmwareGm266dns FirmwareJun 17, 2026 Oct 27, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password. |
1Lenovo 3G263dns Firmware Gm265dn FirmwareGm266dns FirmwareJun 17, 2026 Oct 27, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack...Show more |
1Lenovo 58Thinkagile Hx1331 Firmware Thinkagile Hx2330 FirmwareThinkagile Hx2331 Firmware+55 moreJun 17, 2026 Oct 25, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not aff...Show more |
1Lenovo 123Thinkagile Hx1021 Edg Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+120 moreJun 17, 2026 Oct 25, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An authenticated XCC user can change permissions for any user through a crafted API command. |
1Lenovo 58Thinkagile Hx1331 Firmware Thinkagile Hx2330 FirmwareThinkagile Hx2331 Firmware+55 moreJun 17, 2026 Oct 25, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. |
1Lenovo 3Diagnostics Hardwarescan AddinHardwarescan PluginJun 17, 2026 Oct 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated pr...Show more |
1Lenovo 2Diagnostics Hardwarescan PluginJun 17, 2026 Oct 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to...Show more |
1Lenovo 3Diagnostics Hardwarescan AddinHardwarescan PluginJun 17, 2026 Oct 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to...Show more |
1Lenovo 2Thinkpad T14s Gen 3 Firmware Thinkpad X13 Gen 3 FirmwareJun 17, 2026 Oct 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
|
1Lenovo 2Thinkpad T14s Gen 3 Firmware Thinkpad X13 Gen 3 FirmwareJun 17, 2026 Oct 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
|
1Lenovo 2Thinkpad T14s Gen 3 Firmware Thinkpad X13 Gen 3 FirmwareJun 17, 2026 Oct 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
|
1Lenovo 25D330 10igl Firmware Ideapad 5 Pro 16ach6 FirmwareIdeapad 5 Pro 16ihu6 Firmware+22 moreJun 17, 2026 Oct 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot se...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Emb...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credentia...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Control...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. |