Vulnerabilities (CVE)

Filtered by vendor Lenovo Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3897 2 Ibm, Lenovo 10 Nextscale Fan Power Controller, Nextscale Fan Power Controller Firmware, Nextscale N1200 Enclosure and 7 more 2022-05-09 7.5 HIGH 9.8 CRITICAL
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.
CVE-2021-3849 2 Ibm, Lenovo 10 Nextscale Fan Power Controller, Nextscale Fan Power Controller Firmware, Nextscale N1200 Enclosure and 7 more 2022-05-09 7.5 HIGH 9.8 CRITICAL
An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.
CVE-2021-3616 1 Lenovo 6 Smart Camera C2e, Smart Camera C2e Firmware, Smart Camera X3 and 3 more 2021-08-30 7.5 HIGH 9.8 CRITICAL
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.
CVE-2020-8349 1 Lenovo 10 Cloud Networking Operating System, Rackswitch G8272, Rackswitch G8296 and 7 more 2020-10-29 6.8 MEDIUM 9.8 CRITICAL
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL.
CVE-2019-6167 1 Lenovo 8 Ideacentre, Ideapad, Service Bridge and 5 more 2020-08-24 7.5 HIGH 9.8 CRITICAL
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
CVE-2018-9079 1 Lenovo 40 Ez Media \& Backup Center, Ez Media \& Backup Center Firmware, Ix2 and 37 more 2020-08-24 7.5 HIGH 9.8 CRITICAL
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
CVE-2019-6168 1 Lenovo 8 Ideacentre, Ideapad, Service Bridge and 5 more 2020-08-24 7.5 HIGH 9.8 CRITICAL
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
CVE-2019-6188 1 Lenovo 784 130-14ikb, 130-14ikb Firmware, 130-15ikb and 781 more 2020-08-24 7.5 HIGH 9.8 CRITICAL
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
CVE-2017-17833 5 Canonical, Debian, Lenovo and 2 more 61 Ubuntu Linux, Debian Linux, Bm Nextscale Fan Power Controller and 58 more 2020-05-15 7.5 HIGH 9.8 CRITICAL
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
CVE-2015-5684 1 Lenovo 54 B50-10, B50-10 Firmware, Edge 15 and 51 more 2020-04-01 10.0 HIGH 9.8 CRITICAL
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.
CVE-2019-6177 1 Lenovo 1 Solution Center 2019-10-09 7.5 HIGH 9.8 CRITICAL
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Lenovo Vantage or Lenovo Diagnostics in April 2018.
CVE-2017-3758 1 Lenovo 1 Service Framework 2019-10-03 7.5 HIGH 9.8 CRITICAL
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
CVE-2017-3761 1 Lenovo 1 Service Framework 2019-10-03 10.0 HIGH 9.8 CRITICAL
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.
CVE-2018-14066 3 Google, Infinixmobility, Lenovo 3 Android, Infinix X571, Lenovo A7020 2018-09-21 7.5 HIGH 9.8 CRITICAL
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.
CVE-2017-3774 2 Ibm, Lenovo 43 Bladecenter Hs22, Bladecenter Hs23, Bladecenter Hs23e and 40 more 2018-05-24 7.5 HIGH 9.8 CRITICAL
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.
CVE-2016-8233 1 Lenovo 1 Xclarity Administrator 2017-03-03 5.0 MEDIUM 9.8 CRITICAL
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.