Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad | x31 |
| lenovo | thinkpad | t41 |
| lenovo | thinkpad | x60 |
| lenovo | thinkpad | t42p |
| lenovo | thinkpad | t60p |
| lenovo | thinkpad | r51 |
| lenovo | thinkpad | t42 |
| lenovo | thinkpad | t41p |
| lenovo | thinkpad | x60s |
| intel | pro_1000_lan_adapter | 135400 |
| lenovo | thinkpad | x60_tablet |
| lenovo | thinkpad | r50e |
| lenovo | thinkpad | x32 |
| lenovo | thinkpad | x40 |
| lenovo | thinkpad | r50p |
| lenovo | thinkpad | r50 |
| lenovo | thinkpad | t60 |
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | automated_solutions | 1.0 |
| lenovo | access_support | * |
Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | automated_solutions | 1.0 |
| lenovo | access_support | * |
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | automated_solutions | 1.0 |
| lenovo | access_support | * |
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkvantage_system_update | * |
| lenovo | thinkvantage_system_update | 3.13 |
Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | resuce_and_recovery | 4.20 |
| lenovo | resuce_and_recovery | 4.20.0512 |
| lenovo | resuce_and_recovery | 4.20.0511 |
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | veriface | iii |
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad_bluetooth_with_enhanced_data_rate_software | * |
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| android | 4.0.3 | |
| android | 4.0.4 | |
| lenovo | shareit | * |
| android | 4.0 | |
| android | 4.2 | |
| android | 4.1.2 | |
| android | * | |
| android | 4.0.1 | |
| android | 4.2.1 | |
| android | 4.1 | |
| android | 4.3 | |
| android | 4.0.2 | |
| android | 4.2.2 |
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_update | * |
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_update | * |
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_update | * |
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_compute_node_eus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_compute_node_eus | 7.7 |
| lenovo | emc_px12-450r_ivx | * |
| redhat | enterprise_linux_server_eus | 7.4 |
| arista | eos | 4.13 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_aus | 7.6 |
| arista | eos | 4.14 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.6 |
| redhat | virtualization | 3.0 |
| redhat | enterprise_linux_server_eus | 7.1 |
| redhat | enterprise_linux_for_power_big_endian | 7.0 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.2 |
| redhat | openstack | 6.0 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.1_ppc64 |
| qemu | qemu | * |
| arista | eos | 4.15 |
| redhat | enterprise_linux_compute_node_eus | 7.2 |
| redhat | enterprise_linux_compute_node_eus | 7.1 |
| redhat | enterprise_linux_server_aus | 7.3 |
| lenovo | emc_px12-400r_ivx | * |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.2_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.4_ppc64 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.3 |
| redhat | enterprise_linux_server_tus | 7.7 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.5_ppc64 |
| arista | eos | 4.12 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.7 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.7 |
| redhat | enterprise_linux_compute_node_eus | 7.5 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.3_ppc64 |
| redhat | openstack | 5.0 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.7_ppc64 |
| redhat | enterprise_linux_compute_node_eus | 7.3 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.6_ppc64 |
| redhat | enterprise_linux_compute_node_eus | 7.6 |
| linux | linux_kernel | * |
| redhat | enterprise_linux_server_from_rhui | 7.0 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.4 |
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | usb_enhanced_performance_keyboard | * |
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | fingerprint_manager | * |
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkserver_rd350_firmware | * |
| lenovo | thinkserver_rd450 | * |
| lenovo | thinkserver_rd550 | * |
| lenovo | thinkserver_rd450_firmware | * |
| lenovo | thinkserver_rd350 | * |
| lenovo | thinkserver_td350 | * |
| lenovo | thinkserver_rd650 | * |
| lenovo | thinkserver_td350_firmware | * |
| lenovo | thinkserver_rd550_firmware | * |
| lenovo | thinkserver_rd650_firmware | * |
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkserver_system_manager_baseboard_management_controller_firmware | * |
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkserver_system_manager_baseboard_management_controller_firmware | 118.71532 |
Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | mouse_suite | * |
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_update | * |
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | switch_center | * |
| ibm | system_networking_switch_center | * |
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | switch_center | * |
| ibm | system_networking_switch_center | * |
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | switch_center | * |
| ibm | system_networking_switch_center | * |
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | switch_center | * |
| ibm | system_networking_switch_center | * |
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | emc_firmware | 4.1.204.33661 |
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_system_update | * |
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_system_update | * |
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 3.7s_3.7.4s |
| cisco | ios_xe | 3.11s_3.11.0s |
| cisco | ios_xe | 3.6s_3.6.0s |
| cisco | ios_xe | 3.4s_3.4.0as |
| cisco | ios_xe | 3.13s_3.13.2as |
| cisco | ios_xe | 3.6s_3.6.1s |
| cisco | ios_xe | 3.3sg_3.3.0sg |
| cisco | ios_xe | 3.4s_3.4.6s |
| cisco | ios_xe | 3.7s_3.7.1s |
| cisco | ios_xe | 3.15s_3.15.1s |
| cisco | ios_xe | 3.6e_3.6.2e |
| cisco | ios_xe | 3.10s_3.10.5s |
| cisco | ios_xe | 3.10s_3.10.2s |
| cisco | ios_xe | 3.14s_3.14.0s |
| cisco | ios_xe | 3.15s_3.15.1cs |
| cisco | ios_xe | 3.16s_3.16.0cs |
| cisco | ios_xe | 3.8s_3.8.1s |
| cisco | ios_xe | 3.4s_3.4.2s |
| cisco | ios_xe | 3.5e_3.5.3e |
| cisco | ios_xe | 3.5e_3.5.2e |
| cisco | ios_xe | 3.8e_3.8.0e |
| cisco | ios_xe | 3.4sg_3.4.4sg |
| cisco | ios_xe | 3.5s_3.5.2s |
| cisco | ios_xe | 3.3s_3.3.0s |
| cisco | ios_xe | 3.10s_3.10.1s |
| cisco | ios_xe | 3.16s_3.16.0s |
| cisco | ios_xe | 3.9s_3.9.0as |
| cisco | ios_xe | 3.4s_3.4.1s |
| cisco | ios_xe | 3.7s_3.7.3s |
| cisco | ios_xe | 3.10s_3.10.4s |
| cisco | ios_xe | 3.11s_3.11.3s |
| cisco | ios_xe | 3.9s_3.9.0s |
| cisco | ios_xe | 3.12s_3.12.1s |
| sun | opensolaris | snv_124 |
| cisco | ios_xe | 3.5e_3.5.1e |
| cisco | ios_xe | 3.9s_3.9.1s |
| cisco | ios_xe | 3.10s_3.10.0s |
| cisco | ios_xe | 3.3sg_3.3.2sg |
| cisco | ios_xe | 3.7e_3.7.0e |
| cisco | ios_xe | 3.4s_3.4.3s |
| cisco | ios_xe | 3.5s_3.5.1s |
| cisco | ios_xe | 3.13s_3.13.0s |
| cisco | ios_xe | 3.8s_3.8.0s |
| cisco | ios_xe | 3.4s_3.4.4s |
| cisco | ios_xe | 3.6e_3.6.3e |
| cisco | ios_xe | 3.3xo_3.3.0xo |
| zzinc | keymouse_firmware | 3.08 |
| cisco | ios_xe | 3.7e_3.7.2e |
| cisco | ios_xe | 3.4sg_3.4.3sg |
| cisco | ios_xe | 3.9s_3.9.2s |
| cisco | ios_xe | 3.9s_3.9.1as |
| cisco | ios_xe | 3.11s_3.11.2s |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| cisco | ios_xe | 3.4sg_3.4.6sg |
| cisco | ios_xe | 3.3xo_3.3.2xo |
| cisco | ios_xe | 3.6e_3.6.2ae |
| cisco | ios_xe | 3.10s_3.10.6s |
| cisco | ios_xe | 3.11s_3.11.1s |
| cisco | ios_xe | 3.17s_3.17.0s |
| cisco | ios_xe | 3.15s_3.15.2s |
| cisco | ios_xe | 3.12s_3.12.4s |
| cisco | ios_xe | 3.14s_3.14.3s |
| cisco | ios_xe | 3.4sg_3.4.0sg |
| cisco | ios_xe | 3.5s_3.5.0s |
| cisco | ios_xe | 3.15s_3.15.0s |
| cisco | ios_xe | 3.10s_3.10.1xbs |
| cisco | ios_xe | 3.7s_3.7.5s |
| cisco | ios_xe | 3.7s_3.7.6s |
| cisco | ios_xe | 3.4sg_3.4.2sg |
| cisco | ios_xe | 3.13s_3.13.2s |
| cisco | ios_xe | 3.16s_3.16.1as |
| cisco | ios_xe | 3.11s_3.11.4s |
| cisco | ios_xe | 3.12s_3.12.2s |
| cisco | ios_xe | 3.4s_3.4.5s |
| cisco | ios_xe | 3.16s_3.16.1s |
| lenovo | thinkcentre_e75s_firmware | * |
| cisco | ios_xe | 3.14s_3.14.1s |
| zyxel | gs1900-10hp_firmware | * |
| cisco | ios_xe | 3.7s_3.7.2ts |
| cisco | ios_xe | 3.8e_3.8.1e |
| cisco | ios_xe | 3.3s_3.3.2s |
| cisco | ios_xe | 3.4sg_3.4.5sg |
| cisco | ios_xe | 3.7e_3.7.1e |
| cisco | ios_xe | 3.6e_3.6.0e |
| cisco | ios_xe | 3.10s_3.10.3s |
| cisco | ios_xe | 3.7s_3.7.2s |
| cisco | ios_xe | 3.12s_3.12.3s |
| cisco | ios_xe | 3.13s_3.13.4s |
| cisco | ios_xe | 3.13s_3.13.1s |
| cisco | ios_xe | 3.6s_3.6.2s |
| cisco | ios_xe | 3.7e_3.7.3e |
| cisco | ios_xe | 3.14s_3.14.2s |
| cisco | ios_xe | 3.3xo_3.3.1xo |
| cisco | ios_xe | 3.3sg_3.3.1sg |
| cisco | ios_xe | 3.4sg_3.4.1sg |
| cisco | ios_xe | 3.4sg_3.4.7sg |
| cisco | ios_xe | 3.13s_3.13.0as |
| cisco | ios_xe | 3.7s_3.7.7s |
| cisco | ios_xe | 3.13s_3.13.3s |
| cisco | ios_xe | 3.12s_3.12.0s |
| cisco | ios_xe | 3.3s_3.3.1s |
| cisco | ios_xe | 3.7s_3.7.4as |
| netgear | jr6150_firmware | * |
| cisco | ios_xe | 3.4s_3.4.0s |
| cisco | ios_xe | 3.6e_3.6.1e |
| cisco | ios_xe | 3.5e_3.5.0e |
| cisco | ios_xe | 3.7s_3.7.0s |
| cisco | ios_xe | 3.8s_3.8.2s |
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
| cisco | ios_xe | 3.9.0as |
| cisco | ios_xe | 3.10.1xbs |
| cisco | ios_xe | 3.8.2s |
| cisco | ios_xe | 3.9.1as |
| cisco | ios_xe | 3.10.2s |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| cisco | ios_xe | 3.9.2s |
| cisco | ios_xe | 3.8.0s |
| cisco | ios_xe | 3.10.1s |
| cisco | ios_xe | 3.8.1s |
| cisco | ios_xe | 3.9.1s |
| sun | opensolaris | snv_124 |
| cisco | ios_xe | 3.9.0s |
| zzinc | keymouse_firmware | 3.08 |
| lenovo | thinkcentre_e75s_firmware | * |
| cisco | ios_xe | 3.11.0s |
| cisco | ios_xe | 3.10.0s |
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | shareit | * |
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | shareit | * |
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | shareit | * |
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | shareit | 3.0.18_ww |
The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | solution_center | * |
Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | fingerprint_manager | * |
| lenovo | touch_fingerprint | * |
UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | accelerator_application | - |
Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent scheme URL attack."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | shareit | 3.5.98_ww |
Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | shareit | 3.5.98_ww |
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass the Secure Boot protection mechanism by leveraging an AMI test key.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | bios | - |
The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | solution_center | * |
Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Services.SystemService StartProxy command with a named pipe created in advance and crafted .NET assembly.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | solution_center | * |
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.2 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H | 1.5 | 6.0 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | bios_efi_driver | - |
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | km632_firmware | - |
| dell | km714_firmware | * |
| lenovo | ultraslim_firmware | - |
| amazonbasics | firmware | - |
| logitech | unifying_firmware | * |
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | converged_hx5510_appliance | 5.05 |
| lenovo | system_x3750_m4 | 5.05 |
| lenovo | thinkagile_cx2200 | 5.05 |
| hp | ethernet_10gb_2-port_562flr-sfp+ | * |
| lenovo | thinkserver_rd450 | 5.05 |
| lenovo | thinkserver_sd350 | 5.05 |
| lenovo | system_x3550_m5 | 5.05 |
| intel | ethernet_controller_xl710_firmware | * |
| lenovo | converged_hx5500_appliance | 5.05 |
| lenovo | thinkserver_td350 | 5.05 |
| lenovo | system_x3950_x6 | 5.05 |
| hp | ethernet_10gb_4-port_563sfp+ | * |
| lenovo | thinkserver_rd650 | 5.05 |
| hp | proliant_xl260a_g9_server | * |
| lenovo | system_x3650_m5 | 5.05 |
| lenovo | thinkserver_rd550 | 5.05 |
| intel | ethernet_controller_x710_firmware | * |
| hp | ethernet_10gb_2-port_562sfp+ | * |
| lenovo | nextscale_nx360_m5 | 5.05 |
| lenovo | system_x3500_m5 | 5.05 |
| lenovo | converged_hx_series | 5.05 |
| lenovo | converged_hx7500_appliance | 5.05 |
| lenovo | thinkagile_cx4200 | 5.05 |
| lenovo | converged_hx7510_appliance | 5.05 |
| lenovo | thinkserver_rd350 | 5.05 |
| lenovo | thinkagile_cx4600 | 5.05 |
| lenovo | system_x3250_m5 | 5.05 |
| lenovo | system_x3850_x6 | 5.05 |
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are used internally by LXCA code.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad_w540_bios | - |
| lenovo | thinkpad_e465_bios | - |
| lenovo | thinkpad_t440_bios | - |
| lenovo | thinkpad_l540_bios | - |
| lenovo | thinkpad_t460_bios | - |
| lenovo | thinkpad_e550_bios | - |
| lenovo | thinkpad_yoga_14_460_s3_bios | - |
| lenovo | thinkpad_x240s_bios | - |
| lenovo | thinkpad_yoga_11e_beema_bios | - |
| lenovo | thinkpad_x250_broadwell_bios | - |
| lenovo | thinkpad_11e_skylake_bios | - |
| lenovo | thinkpad_x260_bios | - |
| lenovo | thinkpad_p50_bios | - |
| lenovo | thinkpad_yoga_11e_braswell_bios | - |
| lenovo | thinkpad_edge_e545_bios | - |
| lenovo | thinkpad_x1_carbon_20bx_bios | - |
| lenovo | thinkpad_yoga_11e_bios | - |
| lenovo | thinkpad_p70_bios | - |
| lenovo | thinkpad_t460p_bios | - |
| lenovo | thinkpad_l560_bios | - |
| lenovo | thinkpad_t450s_bios | - |
| lenovo | thinkpad_l450_bios | - |
| lenovo | thinkpad_t550_bios | - |
| lenovo | thinkpad_l440_bios | - |
| lenovo | thinkpad_t560_bios | - |
| lenovo | thinkpad_t460s_bios | - |
| lenovo | thinkpad_tablet_8_bios | - |
| lenovo | thinkpad_x250_sharkbay_bios | - |
| lenovo | thinkpad_t540_bios | - |
| lenovo | thinkpad_s3_yoga_14_bios | - |
| lenovo | thinkpad_e460_bios | - |
| lenovo | thinkpad_yoga_260_s1_bios | - |
| lenovo | thinkpad_11e_broadwell_bios | - |
| lenovo | thinkpad_helix_20ch_bios | - |
| lenovo | thinkpad_p50s_bios | - |
| lenovo | thinkpad_11e_braswell_bios | - |
| lenovo | thinkpad_helix_20cg_bios | - |
| lenovo | thinkpad_x1_carbon_bios | - |
| lenovo | thinkpad_e560_bios | - |
| lenovo | thinkpad_s1_yoga_12_bios | - |
| lenovo | thinkpad_x1_yoga_bios | - |
| lenovo | thinkpad_x140e_amd_bios | - |
| lenovo | thinkpad_tablet_10_bios | - |
| lenovo | thinkpad_13e_bios | - |
| lenovo | thinkpad_e450c_bios | - |
| lenovo | thinkpad_l460_bios | - |
| lenovo | thinkpad_e555_bios | - |
| lenovo | thinkpad_e450_bios | - |
| lenovo | thinkpad_s5_e560p_bios | - |
| lenovo | thinkpad_t440s_bios | - |
| lenovo | thinkpad_t540p_bios | - |
| lenovo | thinkpad_t440p_bios | - |
| lenovo | thinkpad_x1_tablet_bios | - |
| lenovo | thinkpad_edge_e445_bios | - |
| lenovo | thinkpad_11e_beema_bios | - |
| lenovo | thinkpad_yoga_11e_broadwell_bios | - |
| lenovo | thinkpad_edge_e540_bios | - |
| lenovo | thinkpad_s5_yoga_15_bios | - |
| lenovo | thinkpad_x1_carbon_20ax_bios | - |
| lenovo | thinkpad_e455_bios | - |
| lenovo | thinkpad_t450_bios | - |
| lenovo | thinkpad_e565_bios | - |
| lenovo | thinkpad_s540_bios | - |
| lenovo | thinkpad_w550s_bios | - |
| lenovo | thinkpad_x240_bios | - |
| lenovo | thinkpad_e550c_bios | - |
| lenovo | thinkpad_edge_e440_bios | - |
| lenovo | thinkpad_w541_bios | - |
| lenovo | thinkpad_s1_yoga_vpro_bios | - |
| lenovo | thinkpad_s3_s440_bios | - |
| lenovo | thinkpad_t440u_bios | - |
| lenovo | thinkpad_yoga_11e_skylake_bios | - |
| lenovo | thinkpad_10_ella_2_bios | - |
| lenovo | thinkpad_s1_yoga_non_vpro_bios | - |
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_interface_foundation | * |
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | notebook_ideapad_510s_12isk_bios | - |
| lenovo | notebook_e31_80_bios | - |
| lenovo | notebook_k41_80_bios | - |
| lenovo | notebook_ideapad_300_15isk_bios | - |
| lenovo | notebook_ideapad_300_15ibr_bios | - |
| lenovo | notebook_yoga_900s_12isk_bios | - |
| lenovo | notebook_ideapad_300_17isk_bios | - |
| lenovo | notebook_ideapad_300_14ibr_bios | - |
| lenovo | thinkserver_ts150_bios | - |
| lenovo | notebook_miix_710_12ikb_bios | - |
| lenovo | notebook_e40_80_bios | - |
| lenovo | notebook_ideapad_300_14isk_bios | - |
| lenovo | notebook_yoga_510_14isk_bios | - |
| lenovo | notebook_g40_80_bios | - |
| lenovo | notebook_e41_80_bios | - |
| lenovo | notebook_xiaoxin_air_12_bios | - |
| lenovo | notebook_yoga_510_15isk_bios | - |
| lenovo | thinkserver_ts450_bios | - |
| lenovo | notebook_yoga_710_11isk_bios | - |
| lenovo | notebook_110_14ibr_bios | - |
| lenovo | notebook_110_15ibr_bios | - |
| lenovo | notebook_g50_80_touch_bios | - |
| lenovo | notebook_yoga_900_13isk_bios | - |
| lenovo | bios | - |
| lenovo | notebook_g50_80_bios | - |
| lenovo | notebook_b70_80_bios | - |
| lenovo | notebook_yoga_710_11ikb_bios | - |
| lenovo | notebook_e51_80_bios | - |
| lenovo | notebook_k21_80_bios | - |
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-428,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | edge_keyboard_driver | * |
| lenovo | slim_usb_keyboard_driver | * |
The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-19,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | flex_system_x280_m6_bios | - |
| lenovo | system_x3550_m5_bios | - |
| lenovo | flex_system_x240_m5_bios | - |
| lenovo | system_x3650_m5_bios | - |
| lenovo | flex_system_x880_x6_bios | - |
| lenovo | system_x3500_m5_bios | - |
| lenovo | flex_system_x480_x6_bios | - |
| lenovo | nextscale_nx360_m5_bios | - |
| lenovo | system_x3250_m6_bios | - |
| lenovo | system_x3950_x6_bios | - |
| lenovo | system_x3850_x6_bios | - |
Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local users to execute code with elevated privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | transition | - |
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_service_bridge | - |
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_service_bridge | - |
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_service_bridge | - |
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_service_bridge | - |
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | customer_care_software_development_kit | * |
Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkserver_firmware | * |
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | updates | - |
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 14.04 |
| redhat | enterprise_linux_desktop | 6.0 |
| lenovo | thinkserver_rd350g_firmware | - |
| redhat | enterprise_linux_server | 7.0 |
| lenovo | thinksystem_sr630_firmware | - |
| lenovo | thinkserver_rd450_firmware | * |
| lenovo | xclarity_administrator | * |
| lenovo | cmm | * |
| openslp | openslp | 1.0.2 |
| lenovo | thinkserver_td350_firmware | * |
| lenovo | thinksystem_hr630x_firmware | - |
| lenovo | thinkserver_rd450x_firmware | - |
| openslp | openslp | 1.1.0 |
| lenovo | thinkserver_sd350_firmware | - |
| redhat | enterprise_linux_desktop | 7.0 |
| lenovo | storage_n4610_firmware | * |
| redhat | enterprise_linux_server | 6.0 |
| lenovo | thinkserver_rd350_firmware | * |
| lenovo | thinkserver_rd540_firmware | * |
| lenovo | thinksystem_hr650x_firmware | - |
| lenovo | thinkserver_rd340_firmware | * |
| lenovo | thinkserver_rd440_firmware | * |
| lenovo | fan_power_controller | * |
| lenovo | storage_n3310_firmware | * |
| lenovo | imm1 | * |
| redhat | enterprise_linux_workstation | 6.0 |
| lenovo | thinkserver_rd650_firmware | * |
| redhat | enterprise_linux_server_tus | 7.6 |
| lenovo | thinkserver_rd640_firmware | * |
| redhat | enterprise_linux_server_eus | 7.6 |
| lenovo | thinkserver_rs160_firmware | * |
| redhat | enterprise_linux_server_aus | 7.6 |
| canonical | ubuntu_linux | 16.04 |
| lenovo | thinkserver_rd350x_firmware | - |
| lenovo | thinkserver_td340_firmware | * |
| lenovo | flex_system_fc3171_8gb_san_switch_firmware | * |
| lenovo | bm_nextscale_fan_power_controller | * |
| lenovo | thinkserver_rq750_firmware | * |
| lenovo | thinkserver_ts460_firmware | * |
| debian | debian_linux | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| lenovo | thinkserver_rd550_firmware | * |
| lenovo | imm2 | * |
| redhat | enterprise_linux_server_eus | 7.5 |
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | active_protection_system | 1.01b |
| lenovo | active_protection_system | 1.40 |
| lenovo | active_protection_system | 1.77.0.20 |
| lenovo | active_protection_system | 1.82.0.06 |
| lenovo | active_protection_system | 1.76 |
| lenovo | active_protection_system | 1.51 |
| lenovo | active_protection_system | 1.77.0.8 |
| lenovo | active_protection_system | 1.78.0.11 |
| lenovo | active_protection_system | 1.80.3.00 |
| lenovo | active_protection_system | 1.80.8.00 |
| lenovo | active_protection_system | 1.71 |
| lenovo | active_protection_system | 1.75 |
| lenovo | active_protection_system | 1.77.0.11 |
| lenovo | active_protection_system | 1.31 |
| lenovo | active_protection_system | 1.73 |
| lenovo | active_protection_system | 1.77.0.9 |
| lenovo | active_protection_system | 1.20b |
| lenovo | active_protection_system | 1.23 |
| lenovo | active_protection_system | 1.82.0.03 |
| lenovo | active_protection_system | 1.33b |
| lenovo | active_protection_system | 1.82.0.10 |
| lenovo | active_protection_system | 1.52 |
| lenovo | active_protection_system | 1.54 |
| lenovo | active_protection_system | 1.22 |
| lenovo | active_protection_system | 1.62 |
| lenovo | active_protection_system | 1.81.0.08 |
| lenovo | active_protection_system | 1.70 |
| lenovo | active_protection_system | 1.80.1.00 |
| lenovo | active_protection_system | 1.32 |
| lenovo | active_protection_system | 1.41 |
| lenovo | active_protection_system | 1.64 |
| lenovo | active_protection_system | 1.72 |
| lenovo | active_protection_system | 1.63 |
| lenovo | active_protection_system | 1.61 |
| lenovo | active_protection_system | 1.00b |
| lenovo | active_protection_system | 1.21 |
| lenovo | active_protection_system | 1.30b |
| lenovo | active_protection_system | 1.80.11.00 |
| lenovo | active_protection_system | 1.79.0.03 |
| lenovo | active_protection_system | 1.77.0.5 |
| lenovo | active_protection_system | 1.77.0.26 |
| lenovo | active_protection_system | 1.78.0.10 |
| lenovo | active_protection_system | 1.50 |
| lenovo | active_protection_system | 1.34 |
| lenovo | active_protection_system | 1.53 |
| lenovo | active_protection_system | 1.78.0.09 |
| lenovo | active_protection_system | 1.74 |
| lenovo | active_protection_system | 1.77.0.7 |
| lenovo | active_protection_system | 1.82.0.07 |
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | power_management | 1.67.12.23 |
| lenovo | power_management | 1.67.12.19 |
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents could connect to the Connect2 hotspot and see the contents of files while they are being transferred between the two systems.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | connect2 | * |
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | advanced_settings_utility | * |
| lenovo | toolscenter_dynamic_system_analysis | * |
| lenovo | updatexpress_system_pack_installer | * |
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | integrated_management_module_firmware | * |
| ibm | integrated_management_module_firmware | * |
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative or system level privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad_usb_3.0_ethernet_adapter_driver | - |
Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | nerve_center | - |
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-428,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad_compact_usb_keyboard_driver | - |
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | fabric_en4093r_10gb_firmware | * |
| lenovo | g8272_firmware | * |
| ibm | virtual_fabric_10gb | * |
| lenovo | g8264_firmware | * |
| ibm | g8124_firmware | * |
| ibm | g8264cs_firmware | * |
| lenovo | g8332_firmware | * |
| ibm | fabric_cn4093_10gb_firmware | * |
| lenovo | g8052_firmware | * |
| ibm | g8316_firmware | * |
| ibm | fabric_en4093/en4093r_10gb_firmware | * |
| ibm | en2092_1gb_firmware | * |
| ibm | 1g_l2-7_slb | * |
| ibm | layer_2/3_copper_firmware | * |
| ibm | g8332_firmware | * |
| lenovo | g8264cs_firmware | * |
| ibm | g8052_firmware | * |
| ibm | 1:10g_firmware | * |
| ibm | g8264t_firmware | * |
| ibm | g8264_firmware | * |
| lenovo | si4091_firmware | * |
| ibm | g8124e_firmware | * |
| lenovo | fabric_cn4093_10gb_firmware | * |
| lenovo | g8296_firmware | * |
| lenovo | g8124e_firmware | * |
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkstation_p300_firmware | fbktc6a |
| lenovo | thinkcentre_m4600t/s_firmware | m05kt54a |
| lenovo | thinkcentre_m6600t/s_firmware | fwkt39a |
| lenovo | thinkcentre_m72e_firmware | f1kt71a |
| lenovo | thinkserver_td340_firmware | a3tsb5a |
| lenovo | thinkcentre_m79_firmware | m0lkt12a |
| lenovo | thinkserver_rd340_firmware | - |
| lenovo | thinkserver_ts450_firmware | - |
| lenovo | thinkcentre_m6500t/s_firmware | fbktc5a |
| lenovo | yangtian_me/we_h110_firmware | m05kt61a |
| lenovo | thinkcentre_m8300z_firmware | fvkt42a |
| lenovo | thinkcentre_m9550z_firmware | fukt44a |
| lenovo | yangtian_mc_carrizo-l_firmware | - |
| lenovo | thinkstation_p700_firmware | a5kt86a |
| lenovo | thinkserver_rd440_firmware | a0tsb5a |
| lenovo | thinkcentre_m800z_firmware | fvkt42a |
| lenovo | thinkserver_rd640_firmware | a1tsb5a |
| lenovo | thinkcentre_m700_firmware | m05kt54a |
| lenovo | thinkstation_p320_firmware | - |
| lenovo | thinkstation_d30_(4353)_firmware | a3kt57a |
| lenovo | yangtian_s800_firmware | ffkt43a |
| lenovo | thinkstation_e32_firmware | fbktc6a |
| lenovo | thinkcentre_e75_t/s_firmware | - |
| lenovo | ideacentre_300s-11ish_firmware | - |
| lenovo | thinkstation_p510_firmware | - |
| lenovo | thinkcentre_m4500q_firmware | fhkt66a |
| lenovo | yangtian_mc_h110_firmware | m05kt61a |
| lenovo | thinkcentre_m900z_firmware | fukt39a |
| lenovo | thinkcentre_m700z_firmware | fvkt48a |
| lenovo | thinkcentre_m83_firmware | fbktcga |
| lenovo | ideacentre_510s-23isu_firmware | o2ekt24a |
| lenovo | thinkstation_p710_firmware | - |
| lenovo | yangtian_s3040_firmware | fgkt49a |
| lenovo | thinkcentre_m8600t/s_firmware | fwkt39a |
| lenovo | s500_firmware | m0kkt24a |
| lenovo | yangtian_afh81_firmware | fckt80a |
| lenovo | thinkcentre_e73z_(aio)_firmware | fgkt49a |
| lenovo | thinkcentre_m4500t/s_firmware | fckt78a |
| lenovo | yangtian_afq150_firmware | fwkt57a |
| lenovo | ideacentre_700_firmware | - |
| lenovo | thinkcentre_m7300z_firmware | fvkt42a |
| lenovo | thinkcentre_m73z_(aio)_firmware | fgkt46a |
| lenovo | thinkcentre_e79_firmware | m0lkt12a |
| lenovo | thinkcentre_m900_firmware | fwkt39a |
| lenovo | thinkcentre_m7200z_firmware | fgkt46a |
| lenovo | thinkstation_c30_(1136)_firmware | a1kt57a |
| lenovo | thinkcentre_m910t/s_firmware | - |
| lenovo | thinkserver_rd540_firmware | a1tsb5a |
| lenovo | thinkcentre_m4500k_firmware | fckt78a |
| lenovo | thinkserver_rs140_firmware | fbkt91c |
| lenovo | thinkcentre_e93z_(aio)_firmware | ffkt43a |
| lenovo | thinkstation_p900_firmware | a6kt86a |
| lenovo | thinkcentre_m610_firmware | - |
| lenovo | thinkstation_p410_firmware | - |
| lenovo | thinkcentre_e74s_firmware | m05kt54a |
| lenovo | thinkstation_p500_firmware | a4kt86a |
| lenovo | 63_firmware | fckt78a |
| lenovo | thinkcentre_m710t/s_firmware | - |
| lenovo | thinkcentre_m9500z_firmware | fukt44a |
| lenovo | thinkcentre_m92p_firmware | 9skt95a |
| lenovo | thinkcentre_e74z_firmware | fvkt48a |
| lenovo | thinkstation_p310_firmware | fwkt57a |
| lenovo | v320-15iap_firmware | - |
| lenovo | thinkserver_rq750_firmware | 7.05 |
| lenovo | yangtian_mc_godavari_firmware | m0lkt13a |
| lenovo | ideacentre_510s-08ish_firmware | - |
| lenovo | thinkcentre_m810z_firmware | - |
| lenovo | thinkcentre_e73_firmware | fckt78a |
| lenovo | thinkstation_d30_(4354)_firmware | a3kt57a |
| lenovo | m4500_id_firmware | fckt78a |
| lenovo | thinkstation_c30_(1137)_firmware | a1kt57a |
| lenovo | thinkcentre_e73s_firmware | fckt78a |
| lenovo | yangtian_afh110_firmware | m05kt73a |
| lenovo | thinkcentre_m8200z_firmware | fgkt46a |
| lenovo | thinkcentre_m93_firmware | fbktc5a |
| lenovo | thinkcentre_m73p_firmware | fbktc5a |
| lenovo | thinkcentre_m800_firmware | fwkt39a |
| lenovo | yangtian_mc_h81_firmware | fckt80a |
| lenovo | s200z_firmware | m09kt33a |
| lenovo | thinkcentre_m8250z_firmware | fgkt46a |
| lenovo | thinkcentre_m910x_firmware | - |
| lenovo | thinkcentre_m600_firmware | m00kt44a |
| lenovo | thinkcentre_edge_62z_firmware | f8kt40a |
| lenovo | thinkcentre_e74_firmware | m05kt54a |
| lenovo | thinkserver_ts250_firmware | - |
| lenovo | h50-30g_firmware | fckt78a |
| lenovo | thinkcentre_m8500t/s_firmware | fbktc5a |
| lenovo | thinkstation_s30_(4351)_firmware | a2kt54a |
| lenovo | thinkserver_ts550_firmware | - |
| lenovo | thinkcentre_m83z_(aio)_firmware | fvkt42a |
| lenovo | thinkstation_s30_(4352)_firmware | a2kt54a |
| lenovo | m4500_firmware | fckt78a |
| lenovo | thinkserver_ts150_firmware | fbktc3a |
| lenovo | thinkcentre_x1_aio_firmware | m0hkt32a |
| lenovo | thinkserver_ts140_firmware | fbktc3a |
| lenovo | thinkcentre_m715q_firmware | - |
| lenovo | thinkcentre_m92_firmware | 9skt95a |
| lenovo | thinkcentre_e93_firmware | fbktc5a |
| lenovo | thinkcentre_m73_firmware | fckt78a |
| lenovo | thinkcentre_m7250z_firmware | fgkt46a |
| lenovo | thinkserver_ts240_firmware | fbktc3a |
| lenovo | m4550_id_firmware | fckt78a |
| lenovo | thinkcentre_m93p_firmware | fbktc5a |
| lenovo | thinkstation_e31_firmware | 9skt97a |
| lenovo | thinkcentre_m910q_firmware | - |
| lenovo | thinkcentre_m6600_firmware | fwkt39a |
| lenovo | yangtian_mf/wf_h81_firmware | fckt80a |
| lenovo | thinkcentre_m8350z_firmware | fvkt42a |
| lenovo | thinkstation_p910_firmware | - |
| lenovo | thinkcentre_m6600q_firmware | fwkt39a |
| lenovo | ideacentre_300-20ish_firmware | - |
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | bios | - |
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad_edge_e540 | - |
| lenovo | thinkpad_t560 | - |
| lenovo | thinkpad_t460_bios | - |
| lenovo | thinkpad_e550_bios | - |
| lenovo | thinkpad_yoga_14_460_s3_bios | - |
| lenovo | thinkpad_e450 | - |
| lenovo | thinkpad_tablet_10 | - |
| lenovo | thinkpad_yoga_11e_beema_bios | - |
| lenovo | thinkpad_s3_yoga_14 | - |
| lenovo | thinkpad_x250_broadwell_bios | - |
| lenovo | thinkpad_e450c | - |
| lenovo | thinkpad_11e_skylake_bios | - |
| lenovo | thinkpad_l560 | - |
| lenovo | thinkpad_yoga_11e_bios | - |
| lenovo | thinkpad_s1_yoga_vpro | - |
| lenovo | thinkpad_t450s_bios | - |
| lenovo | thinkpad_l450_bios | - |
| lenovo | thinkpad_l440 | - |
| lenovo | thinkpad_edge_e440 | - |
| lenovo | thinkpad_s1_yoga_12 | - |
| lenovo | thinkpad_t560_bios | - |
| lenovo | thinkpad_s5_e560p | - |
| lenovo | thinkpad_t440u | - |
| lenovo | thinkpad_tablet_8_bios | - |
| lenovo | thinkpad_s3_s440 | - |
| lenovo | thinkpad_11e_broadwell_bios | - |
| lenovo | thinkpad_x1_tablet | - |
| lenovo | thinkpad_p50 | - |
| lenovo | thinkpad_p50s_bios | - |
| lenovo | thinkpad_w540 | - |
| lenovo | thinkpad_x250_broadwell | - |
| lenovo | thinkpad_helix_20cg_bios | - |
| lenovo | thinkpad_x1_carbon_bios | - |
| lenovo | thinkpad_x1_yoga_bios | - |
| lenovo | thinkpad_helix_20cg | - |
| lenovo | thinkpad_x140e_amd_bios | - |
| lenovo | thinkpad_tablet_10_bios | - |
| lenovo | thinkpad_yoga_14_460_s3 | - |
| lenovo | thinkpad_t540p | - |
| lenovo | thinkpad_e450_bios | - |
| lenovo | thinkpad_e550 | - |
| lenovo | thinkpad_s5_yoga_15 | - |
| lenovo | thinkpad_t460p | - |
| lenovo | thinkpad_edge_e445 | - |
| lenovo | thinkpad_p50s | - |
| lenovo | thinkpad_x1_tablet_bios | - |
| lenovo | thinkpad_x260 | - |
| lenovo | thinkpad_11e_beema_bios | - |
| lenovo | thinkpad_yoga_11e_broadwell_bios | - |
| lenovo | thinkpad_p70 | - |
| lenovo | thinkpad_edge_e540_bios | - |
| lenovo | thinkpad_s5_yoga_15_bios | - |
| lenovo | thinkpad_t460s | - |
| lenovo | thinkpad_tablet_8 | - |
| lenovo | thinkpad_t450_bios | - |
| lenovo | thinkpad_t540 | - |
| lenovo | thinkpad_w541 | - |
| lenovo | thinkpad_10_ella_2 | - |
| lenovo | thinkpad_s540_bios | - |
| lenovo | thinkpad_x1_carbon_20bx | - |
| lenovo | thinkpad_yoga_11e_broadwell | - |
| lenovo | thinkpad_x240_bios | - |
| lenovo | thinkpad_e465 | - |
| lenovo | thinkpad_11e_skylake | - |
| lenovo | thinkpad_s540 | - |
| lenovo | thinkpad_x1_carbon_20ax | - |
| lenovo | thinkpad_l460 | - |
| lenovo | thinkpad_e455 | - |
| lenovo | thinkpad_t440u_bios | - |
| lenovo | thinkpad_yoga_11e_skylake_bios | - |
| lenovo | thinkpad_s1_yoga_non_vpro_bios | - |
| lenovo | thinkpad_t440p | - |
| lenovo | thinkpad_w540_bios | - |
| lenovo | thinkpad_e465_bios | - |
| lenovo | thinkpad_t440_bios | - |
| lenovo | thinkpad_l540_bios | - |
| lenovo | thinkpad_x240s_bios | - |
| lenovo | thinkpad_yoga_11e_skylake | - |
| lenovo | thinkpad_x260_bios | - |
| lenovo | thinkpad_yoga_11e | - |
| lenovo | thinkpad_p50_bios | - |
| lenovo | thinkpad_yoga_11e_braswell_bios | - |
| lenovo | thinkpad_edge_e545_bios | - |
| lenovo | thinkpad_x1_carbon_20bx_bios | - |
| lenovo | thinkpad_p70_bios | - |
| lenovo | thinkpad_t460p_bios | - |
| lenovo | thinkpad_t550 | - |
| lenovo | thinkpad_l560_bios | - |
| lenovo | thinkpad_11e_beema | - |
| lenovo | thinkpad_e565 | - |
| lenovo | thinkpad_13e | - |
| lenovo | thinkpad_x240s | - |
| lenovo | thinkpad_yoga_11e_braswell | - |
| lenovo | thinkpad_t550_bios | - |
| lenovo | thinkpad_l440_bios | - |
| lenovo | thinkpad_t460s_bios | - |
| lenovo | thinkpad_t450 | - |
| lenovo | thinkpad_w550s | - |
| lenovo | thinkpad_x250_sharkbay_bios | - |
| lenovo | thinkpad_x240 | - |
| lenovo | thinkpad_t540_bios | - |
| lenovo | thinkpad_s3_yoga_14_bios | - |
| lenovo | thinkpad_e460_bios | - |
| lenovo | thinkpad_yoga_260_s1_bios | - |
| lenovo | thinkpad_l540 | - |
| lenovo | thinkpad_11e_braswell | - |
| lenovo | thinkpad_x140e_amd | - |
| lenovo | thinkpad_helix_20ch_bios | - |
| lenovo | thinkpad_11e_braswell_bios | - |
| lenovo | thinkpad_e560_bios | - |
| lenovo | thinkpad_s1_yoga_12_bios | - |
| lenovo | thinkpad_e555 | - |
| lenovo | thinkpad_11e_broadwell | - |
| lenovo | thinkpad_13e_bios | - |
| lenovo | thinkpad_e450c_bios | - |
| lenovo | thinkpad_edge_e545 | - |
| lenovo | thinkpad_l460_bios | - |
| lenovo | thinkpad_t450s | - |
| lenovo | thinkpad_e555_bios | - |
| lenovo | thinkpad_l450 | - |
| lenovo | thinkpad_helix_20ch | - |
| lenovo | thinkpad_yoga_11e_beema | - |
| lenovo | thinkpad_s5_e560p_bios | - |
| lenovo | thinkpad_t440s_bios | - |
| lenovo | thinkpad_t540p_bios | - |
| lenovo | thinkpad_t440p_bios | - |
| lenovo | thinkpad_e560 | - |
| lenovo | thinkpad_x1_yoga | - |
| lenovo | thinkpad_x250_sharkbay | - |
| lenovo | thinkpad_edge_e445_bios | - |
| lenovo | thinkpad_x1_carbon | - |
| lenovo | thinkpad_t440 | - |
| lenovo | thinkpad_x1_carbon_20ax_bios | - |
| lenovo | thinkpad_yoga_260_s1 | - |
| lenovo | thinkpad_e455_bios | - |
| lenovo | thinkpad_e565_bios | - |
| lenovo | thinkpad_w550s_bios | - |
| lenovo | thinkpad_e460 | - |
| lenovo | thinkpad_t440s | - |
| lenovo | thinkpad_t460 | - |
| lenovo | thinkpad_e550c | - |
| lenovo | thinkpad_e550c_bios | - |
| lenovo | thinkpad_edge_e440_bios | - |
| lenovo | thinkpad_s1_yoga_non_vpro | - |
| lenovo | thinkpad_w541_bios | - |
| lenovo | thinkpad_s1_yoga_vpro_bios | - |
| lenovo | thinkpad_s3_s440_bios | - |
| lenovo | thinkpad_10_ella_2_bios | - |
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | service_framework | - |
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | service_framework | - |
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-354,CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | service_framework | - |
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | service_framework | - |
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | fingerprint_manager_pro | * |
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | enterprise_network_operating_system | * |
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkcentre_m710t_firmware | * |
| lenovo | thinkcentre_m710s_firmware | * |
| lenovo | aio_e95_firmware | * |
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | integrated_management_module_2 | * |
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_x3650_m5_bios | * |
| lenovo | system_x3500_m5_bios | * |
| lenovo | flex_system_x880_bios | * |
| lenovo | nextscale_nx360_m5_bios | * |
| lenovo | flex_system_x480_x6_bios | * |
| lenovo | system_x3550_m5_bios | * |
| lenovo | system_x3250_m6_bios | * |
| lenovo | flex_system_x240_m5_bios | * |
| lenovo | system_x3850_x6_bios | * |
| lenovo | flex_system_x280_x6_bios | * |
| lenovo | system_x3950_x6_bios | * |
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_help | * |
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-755,CWE-755,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | struts | * |
| hp | server_automation | 10.2.0 |
| oracle | weblogic_server | 12.1.3.0.0 |
| lenovo | storage_v5030_firmware | 7.7.1.6 |
| hp | server_automation | 10.0.0 |
| ibm | storwize_v7000_firmware | 7.7.1.6 |
| hp | server_automation | 10.1.0 |
| arubanetworks | clearpass_policy_manager | * |
| lenovo | storage_v5030_firmware | 7.8.1.0 |
| hp | server_automation | 10.5.0 |
| oracle | weblogic_server | 10.3.6.0.0 |
| ibm | storwize_v3500_firmware | 7.8.1.0 |
| ibm | storwize_v3500_firmware | 7.7.1.6 |
| ibm | storwize_v5000_firmware | 7.7.1.6 |
| ibm | storwize_v7000_firmware | 7.8.1.0 |
| hp | server_automation | 9.1.0 |
| netapp | oncommand_balance | - |
| oracle | weblogic_server | 12.2.1.2.0 |
| oracle | weblogic_server | 12.2.1.1.0 |
| ibm | storwize_v5000_firmware | 7.8.1.0 |
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| intel | core_i3 | 4100u |
| intel | core_i7 | 8809g |
| intel | core_i5 | 4210y |
| intel | core_i7 | 4600u |
| intel | core_i5 | 4400e |
| intel | core_i7 | 4760hq |
| intel | core_i5 | 4402e |
| intel | core_i5 | 4690k |
| intel | core_i7 | 6567u |
| intel | core_i3 | 6300 |
| intel | core_i7 | 8709g |
| intel | core_i5 | 4210m |
| intel | core_i5 | 8350u |
| intel | core_i3 | 8100 |
| intel | core_i5 | 8259u |
| lenovo | thinkpad_t470 | - |
| intel | core_i5 | 8500 |
| intel | core_i5 | 4310m |
| intel | core_i7 | 4510u |
| lenovo | thinkpad_t470s | - |
| intel | core_i7 | 6920hq |
| intel | core_i5 | 8200y |
| intel | core_i5 | 4402ec |
| intel | core_i7 | 4610m |
| intel | core_i5 | 7400 |
| intel | core_i7 | 8650u |
| intel | core_i7 | 4702hq |
| intel | core_i3 | 4170t |
| intel | core_i5 | 5250u |
| intel | core_i7 | 4750hq |
| intel | core_i5 | 7300hq |
| intel | core_i5 | 7400t |
| intel | core_i7 | 4790s |
| intel | core_i5 | 4200m |
| intel | core_i5 | 8300h |
| intel | core_i7 | 4722hq |
| lenovo | thinkpad_x1_tablet | - |
| intel | core_i7 | 4610y |
| lenovo | thinkpad_p51 | - |
| lenovo | thinkpad_t470p | - |
| intel | core_i5 | 4570s |
| intel | core_i5 | 8269u |
| intel | core_i3 | 6102e |
| intel | core_i5 | 6350hq |
| intel | core_i7 | 5550u |
| lenovo | thinkpad_x380_yoga | - |
| intel | core_i7 | 4770hq |
| intel | core_i5 | 7500t |
| intel | core_i3 | 4160t |
| intel | core_i7 | 4790k |
| intel | core_i3 | 4360t |
| intel | core_i5 | 4330m |
| intel | core_i7 | 8700b |
| intel | core_i7 | 6500u |
| intel | core_i3 | 8130u |
| lenovo | thinkpad_t25 | - |
| intel | core_i3 | 7300 |
| intel | core_i5 | 4260u |
| lenovo | thinkpad_l580 | - |
| lenovo | thinkpad_e480 | - |
| intel | core_i5 | 6500te |
| intel | core_i7 | 6660u |
| lenovo | thinkpad_p52s | - |
| intel | core_i7 | 6700 |
| intel | core_i5 | 6400t |
| intel | core_i7 | 5850eq |
| intel | core_i3 | 4330te |
| intel | core_i7 | 5950hq |
| intel | core_i7 | 6820hk |
| intel | core_i7 | 4700ec |
| intel | core_i3 | 4350 |
| intel | core_i7 | 4650u |
| intel | core_i7 | 5650u |
| intel | core_i5 | 6442eq |
| intel | core_i7 | 4870hq |
| intel | core_i5 | 4278u |
| intel | core_i3 | 4340te |
| intel | core_i5 | 7200u |
| intel | core_i7 | 5600u |
| intel | core_i5 | 4670t |
| intel | core_i7 | 4710hq |
| intel | core_i5 | 7267u |
| intel | core_i3 | 6100t |
| intel | core_i5 | 6260u |
| intel | core_i3 | 6100te |
| intel | core_i5 | 4200y |
| intel | core_i5 | 4460s |
| intel | core_i7 | 7700 |
| intel | core_i5 | 7442eq |
| intel | core_i5 | 4670 |
| intel | core_i7 | 6820hq |
| intel | core_i7 | 8706g |
| intel | core_i7 | 4500u |
| intel | core_i5 | 5287u |
| intel | core_i5 | 6440eq |
| lenovo | thinkpad_l380 | - |
| intel | core_i5 | 4570r |
| intel | core_i3 | 4360 |
| intel | core_i7 | 5775r |
| intel | core_i7 | 6700k |
| intel | core_i3 | 8100h |
| intel | core_i7 | 5750hq |
| intel | core_i5 | 4302y |
| intel | core_i5 | 8500t |
| lenovo | thinkpad_x270 | - |
| intel | core_i5 | 6287u |
| intel | core_i5 | 8500b |
| intel | core_i5 | 6585r |
| intel | core_i5 | 8600k |
| intel | core_i5 | 4310u |
| intel | core_i3 | 7100 |
| lenovo | thinkpad_p72 | - |
| intel | core_i7 | 8850h |
| intel | core_i7 | 8700k |
| intel | core_i3 | 7020u |
| intel | core_i5 | 7287u |
| intel | core_i7 | 7820hk |
| intel | core_i7 | 4765t |
| intel | core_i3 | 4100m |
| lenovo | thinkpad_e580 | - |
| intel | core_i3 | 4030u |
| intel | core_i5 | 4288u |
| intel | core_i5 | 4690t |
| intel | core_i3 | 6100u |
| intel | core_i5 | 4590 |
| intel | core_i7 | 4785t |
| intel | core_i7 | 6560u |
| intel | core_i3 | 4100e |
| intel | core_i5 | 4202y |
| lenovo | thinkpad_x1_yoga | - |
| intel | core_i7 | 4980hq |
| lenovo | thinkpad_t580 | - |
| intel | core_i7 | 4702mq |
| intel | core_i7 | 8550u |
| intel | core_i3 | 7100e |
| intel | core_i7 | 6700te |
| intel | core_i5 | 5575r |
| intel | core_i3 | 6100e |
| intel | core_i3 | 5020u |
| intel | core_i3 | 4150t |
| intel | core_i3 | 5010u |
| intel | core_i3 | 4330 |
| intel | core_i3 | 7300t |
| intel | core_i5 | 8400b |
| intel | core_i5 | 4300y |
| intel | core_i3 | 6157u |
| intel | core_i5 | 4430 |
| intel | core_i7 | 4712hq |
| intel | core_i7 | 7700hq |
| intel | core_i5 | 4340m |
| intel | core_i7 | 4770te |
| intel | core_i7 | 8559u |
| intel | core_i7 | 4790t |
| intel | core_i7 | 4860hq |
| intel | core_i3 | 4005u |
| intel | core_i5 | 4360u |
| intel | core_i5 | 4570 |
| intel | core_i7 | 4710mq |
| intel | core_i5 | 4690s |
| intel | core_i7 | 4950hq |
| lenovo | thinkpad_p71 | - |
| intel | core_i5 | 4670s |
| intel | core_i5 | 7y54 |
| intel | core_i7 | 8700 |
| intel | core_i5 | 5350h |
| intel | core_i5 | 5675c |
| intel | core_i7 | 8750h |
| intel | core_i3 | 7167u |
| intel | core_i5 | 4440 |
| intel | core_i7 | 7660u |
| intel | core_i5 | 6685r |
| intel | core_i5 | 4440s |
| intel | core_i5 | 6267u |
| intel | core_i5 | 4200h |
| intel | core_i3 | 4130 |
| intel | core_i5 | 8400 |
| intel | core_i5 | 6600t |
| intel | core_i7 | 7700k |
| intel | core_i7 | 4900mq |
| intel | core_i7 | 7567u |
| intel | core_i3 | 6320 |
| intel | core_i5 | 6402p |
| intel | core_i7 | 5557u |
| intel | core_i7 | 4770t |
| lenovo | thinkpad_x280 | - |
| intel | core_i3 | 4010y |
| intel | core_i3 | 4110m |
| intel | core_i5 | 4670r |
| intel | core_i3 | 4158u |
| intel | core_i5 | 4570t |
| intel | core_i7 | 6870hq |
| lenovo | thinkpad_yoga_370 | - |
| intel | core_i5 | 4308u |
| lenovo | thinkpad_t480s | - |
| intel | core_i5 | 6300u |
| intel | core_i3 | 4025u |
| intel | core_i3 | 4340 |
| intel | core_i5 | 8600 |
| intel | core_i7 | 6600u |
| intel | core_i5 | 6500t |
| intel | core_i7 | 6970hq |
| intel | core_i5 | 8400t |
| intel | core_i3 | 6100 |
| intel | core_i7 | 7600u |
| intel | core_i5 | 4220y |
| intel | core_i3 | 6167u |
| intel | core_i3 | 7100t |
| intel | core_i5 | 7500 |
| intel | core_i7 | 4960hq |
| intel | core_i7 | 5500u |
| intel | core_i7 | 4770k |
| intel | core_i3 | 6100h |
| intel | core_i5 | 6360u |
| intel | core_i3 | 4112e |
| intel | core_i3 | 8145u |
| intel | core_i7 | 4578u |
| intel | core_i3 | 7102e |
| lenovo | thinkpad_p52 | - |
| intel | core_i5 | 6600 |
| intel | core_i3 | 6098p |
| intel | core_i5 | 7600k |
| intel | core_i7 | 4770 |
| intel | core_i5 | 5350u |
| intel | core_i3 | 7130u |
| intel | core_i3 | 6006u |
| intel | core_i5 | 4210u |
| intel | core_i5 | 5300u |
| intel | core_i9 | 8950hk |
| intel | core_i5 | 7260u |
| intel | core_i7 | 4771 |
| intel | core_i3 | 4000m |
| intel | core_i7 | 5820k |
| intel | core_i7 | 4770r |
| intel | core_i3 | 8109u |
| intel | core_i7 | 4700hq |
| intel | core_i3 | 4350t |
| intel | core_i7 | 4910mq |
| intel | core_i3 | 7100h |
| intel | core_i5 | 8265u |
| intel | core_i3 | 4160 |
| lenovo | thinkpad_t480 | - |
| intel | core_i3 | 4370 |
| intel | core_i5 | 4250u |
| intel | core_i5 | 4590t |
| lenovo | thinkpad_11e | - |
| intel | core_i5 | 6200u |
| intel | core_i7 | 4702ec |
| intel | core_i5 | 4460t |
| intel | core_i5 | 4422e |
| intel | core_i7 | 5775c |
| intel | core_i3 | 4170 |
| intel | core_i7 | 6820eq |
| intel | core_i5 | 6440hq |
| intel | core_i3 | 4370t |
| intel | core_i7 | 8700t |
| intel | core_i3 | 7100u |
| intel | core_i7 | 4790 |
| intel | core_i7 | 8705g |
| intel | core_i7 | 6785r |
| intel | core_i5 | 4210h |
| intel | core_i5 | 8600t |
| intel | core_i5 | 7600t |
| intel | core_i7 | 8565u |
| intel | core_i5 | 6300hq |
| intel | core_i3 | 4330t |
| intel | core_i5 | 5675r |
| intel | core_i3 | 8300t |
| intel | core_i3 | 4010u |
| intel | core_i7 | 7920hq |
| intel | core_i5 | 7y57 |
| intel | core_i3 | 5157u |
| intel | core_i5 | 4570te |
| intel | core_i7 | 5700hq |
| intel | core_i5 | 6400 |
| intel | core_i3 | 4120u |
| intel | core_i5 | 4590s |
| intel | core_i5 | 4200u |
| intel | core_i7 | 4720hq |
| intel | core_i5 | 5200u |
| intel | core_i3 | 7101te |
| intel | core_i3 | 6300t |
| intel | core_i7 | 4770s |
| intel | core_i7 | 4700eq |
| lenovo | thinkpad_p51s | - |
| intel | core_i7 | 5700eq |
| intel | core_i7 | 6822eq |
| intel | core_i7 | 5850hq |
| intel | core_i7 | 6770hq |
| intel | core_i5 | 4410e |
| intel | core_i3 | 8350k |
| intel | core_i7 | 6700hq |
| intel | core_i3 | 4110e |
| intel | core_i7 | 4850hq |
| intel | core_i5 | 7600 |
| intel | core_i3 | 8100t |
| intel | core_i5 | 4460 |
| intel | core_i3 | 4150 |
| intel | core_i3 | 7350k |
| lenovo | thinkpad_l380_yoga | - |
| intel | core_i7 | 8500y |
| intel | core_i7 | 7y75 |
| intel | core_i5 | 5257u |
| intel | core_i5 | 7360u |
| intel | core_i5 | 4300u |
| intel | core_i7 | 4712mq |
| intel | core_i3 | 7320 |
| intel | core_i7 | 4550u |
| intel | core_i7 | 7820eq |
| intel | core_i7 | 7820hq |
| intel | core_i3 | 4020y |
| intel | core_i3 | 5005u |
| intel | core_i3 | 7101e |
| lenovo | thinkpad_x1_carbon | - |
| intel | core_i5 | 4430s |
| intel | core_i3 | 4012y |
| intel | core_i5 | 4350u |
| intel | core_i3 | 4030y |
| intel | core_i3 | 5015u |
| intel | core_i5 | 4300m |
| intel | core_i7 | 4800mq |
| intel | core_i7 | 4810mq |
| intel | core_i3 | 4102e |
| intel | core_i3 | 4130t |
| intel | core_i5 | 4670k |
| intel | core_i5 | 6500 |
| intel | core_i7 | 7700t |
| intel | core_i7 | 7560u |
| intel | core_i5 | 8400h |
| lenovo | thinkpad_l480 | - |
| intel | core_i7 | 8086k |
| intel | core_i7 | 7500u |
| intel | core_i7 | 6650u |
| intel | core_i5 | 8305g |
| intel | core_i5 | 7440hq |
| intel | core_i7 | 4558u |
| intel | core_i5 | 4258u |
| intel | core_i5 | 6600k |
| intel | core_i5 | 7300u |
| intel | core_i3 | 8300 |
| intel | core_i5 | 7440eq |
| intel | core_i5 | 8250u |
| intel | core_i7 | 4700mq |
| lenovo | thinkpad_t570 | - |
| intel | core_i7 | 6700t |
| intel | core_i7 | 4600m |
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_integrator | * |
In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_integrator | * |
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.8 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkpad_l380_firmware | * |
| lenovo | e52-80_isk_firmware | * |
| lenovo | thinkpad_p51s_firmware | * |
| lenovo | e52-80_firmware | * |
| lenovo | thinkpad_x280_firmware | * |
| lenovo | thinkpad_s1_firmware | * |
| lenovo | v510-14ikb_firmware | * |
| lenovo | e42-80_isk_firmware | * |
| lenovo | thinkpad_t470_firmware | * |
| lenovo | thinkpad_p51_firmware | * |
| lenovo | thinkpad_l580_firmware | * |
| lenovo | thinkpad_p52_firmware | * |
| lenovo | thinkpad_x380_yoga_firmware | * |
| lenovo | miix_720-12ikb_firmware | * |
| lenovo | v310-14isk_firmware | * |
| lenovo | v510-15ikb_firmware | * |
| lenovo | v310-15isk_firmware | * |
| lenovo | thinkpad_p72_firmware | * |
| lenovo | thinkpad_t580_firmware | * |
| lenovo | thinkpad_p52s_firmware | * |
| lenovo | thinkpad_x1_carbon_firmware | * |
| lenovo | thinkpad_yoga_11e_firmware | * |
| lenovo | v310-15ikb_firmware | * |
| lenovo | thinkpad_x1_yoga_firmware | * |
| lenovo | thinkpad_x1_tablet_firmware | * |
| lenovo | thinkpad_t25_firmware | * |
| lenovo | thinkpad_e580_firmware | * |
| lenovo | thinkpad_e480_firmware | * |
| lenovo | thinkpad_t480_firmware | * |
| lenovo | thinkpad_yoga_370_firmware | * |
| lenovo | v310-14ikb_firmware | * |
| lenovo | thinkpad_p71_firmware | * |
| lenovo | thinkpad_x270_firmware | * |
| lenovo | thinkpad_t570_firmware | * |
| lenovo | thinkpad_t470p_firmware | * |
| lenovo | e42-80_firmware | * |
| lenovo | thinkpad_t480s_firmware | * |
| lenovo | thinkpad_t470s_firmware | * |
| lenovo | thinkpad_l480_firmware | * |
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional privilege is granted to the attacker beyond what is already possessed to run MapDrv.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_update | * |
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.
CVSS 2.0
Severity: LOW
Problem Type: CWE-312,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_administrator | * |
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovo_help | * |
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_x3250_m5_firmware | * |
| ibm | bladecenter_hs22_firmware | * |
| lenovo | nextscale_nx360_m5_firmware | * |
| ibm | flex_system_x880_m4_firmware | * |
| lenovo | flex_system_x440_m4_firmware | * |
| ibm | bladecenter_hs23_firmware | * |
| ibm | system_x3650_m4_bd_firmware | * |
| ibm | flex_system_x280_m4_firmware | * |
| lenovo | system_x3750_m4_firmware | * |
| ibm | system_x3300_m4_firmware | * |
| ibm | system_x3550_m4_firmware | * |
| ibm | flex_system_x440_m4_firmware | * |
| lenovo | flex_system_x480_x6_firmware | * |
| lenovo | system_x3650_m5_firmware | * |
| ibm | idataplex_dx360_m4_water_cooled_firmware | * |
| ibm | idataplex_dx360_m4_firmware | * |
| lenovo | system_x3250_m6_firmware | * |
| ibm | bladecenter_hs23e_firmware | * |
| ibm | system_x3100_m4_firmware | * |
| ibm | system_x3250_m4_firmware | * |
| ibm | nextscale_nx360_m4_firmware | * |
| lenovo | flex_system_x240_m5_firmware | * |
| ibm | flex_system_x220_m4_firmware | * |
| lenovo | system_x3950_x6_firmware | * |
| lenovo | flex_system_x240_m4_firmware | * |
| lenovo | flex_system_x880_firmware | * |
| ibm | system_x3750_m4_firmware | * |
| ibm | system_x3850_x6_firmware | * |
| ibm | system_x3650_m4_hd_firmware | * |
| ibm | system_x3650_m4_firmware | * |
| ibm | system_x3100_m5_firmware | * |
| ibm | system_x3530_m4_firmware | * |
| lenovo | system_x3550_m5_firmware | * |
| lenovo | flex_system_x280_x6_firmware | * |
| ibm | flex_system_x240_m4_firmware | * |
| lenovo | system_x3500_m5_firmware | * |
| lenovo | system_x3850_x6_firmware | * |
| ibm | flex_system_x480_m4_firmware | * |
| ibm | system_x3500_m4_firmware | * |
| ibm | flex_system_x222_m4_firmware | * |
| ibm | system_x3630_m4_firmware | * |
| ibm | system_x3950_x6_firmware | * |
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H | 0.7 | 5.2 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | 320s-14ikb | * |
| hp | 7000-15_u42_firmware | * |
| hp | yoga_720-13ikbr_firmware | * |
| hp | lenovo_ideapad_320s-14ikbr_firmware | - |
| hp | 520-15ikbrn_firmware | * |
| hp | 320-15ikbrn_touch_firmware | * |
| hp | 7000_u42_firmware | * |
| hp | lenovo_y720-15ikb_firmware | * |
| hp | r720-15ikbn_firmware | * |
| hp | yoga_720-13ikb_firmware | * |
| lenovo | v510-15ikb_firmware | * |
| hp | e43-80_kbl_firmware | * |
| lenovo | v310-15isk_firmware | * |
| hp | flex_5-1570_firmware | * |
| hp | lenovo_ideapad_320-15ikb(i+n)_firmware | - |
| hp | y720-15ikb_firmware | * |
| hp | v330-14ikb_firmware | * |
| hp | 710s_plus-13ikb_16g_firmware | * |
| hp | lenovo_ideapad_flex_5-1570_firmware | * |
| hp | lenovo_ideapad_520s-14ikbr_firmware | - |
| hp | lenovo_ideapad_320-15abr_firmware | - |
| hp | r720-15ikba_firmware | * |
| hp | y520-15ikbn_firmware | * |
| hp | 320s-15isk_firmware | * |
| hp | 710s_plus-3ikb_firmware | * |
| hp | b320-14ikb_firmware | - |
| hp | lenovo_yoga_520-15ikb_firmware | * |
| hp | y520-15ikba_firmware | * |
| hp | lenovo_ideapad_y520-15ikbn_firmware | - |
| hp | lenovo_tianyi_310-15ikb_firmware | - |
| hp | 510s-14isk_firmware | * |
| hp | lenovo_y520-15ikba_firmware | * |
| hp | lenovo_ideapad_720s-14ikb_firmware | * |
| hp | lenovo_ideapad_320-14ikb(i+n)_firmware | - |
| lenovo | e52-80_firmware | * |
| hp | 320-15ikbrn_firmware | * |
| lenovo | v510-14ikb_firmware | * |
| hp | lenovo_yoga_520-14ikb_firmware | * |
| hp | ideapad_2in1_14_firmware | - |
| hp | nano110-15ikb_firmware | * |
| hp | yoga_510-14isk_firmware | * |
| lenovo | v310-14isk_firmware | * |
| hp | 310s-14isk_firmware | * |
| hp | 520s-14ikb_firmware | * |
| hp | lenovo_ideapad_320s-15ikbr_firmware | - |
| hp | yoga_310-11iap_firmware | * |
| hp | 320s-15ikb_firmware | * |
| hp | rescuer_y520-15ikbm_firmware | * |
| hp | lenovo_ideapad_320-14ikb(i+a)_firmware | - |
| lenovo | v310-15ikb_firmware | * |
| hp | 720s-13ikb_firmware | * |
| hp | 320-17ikbrn | * |
| hp | yoga_720-15ikb_firmware | * |
| hp | flex_4-1470_firmware | * |
| hp | flex_5-1470_firmware | * |
| hp | v330-14isk_firmware | * |
| lenovo | v310-14ikb_firmware | * |
| hp | lenovo_ideapad_flex_5-1470_firmware | * |
| hp | lenovo_y520-15ikbm_firmware | * |
| hp | 710s_plus_touch-13ikb_firmware | * |
| hp | lenovo_tianyi_310-14ikb_firmware | - |
| hp | miix_720-12ikb | * |
| hp | xiaoxinair13ikbpro_firmware | * |
| hp | rescuer_r720-15ikbm_firmware | * |
| lenovo | e42-80_firmware | * |
| hp | nano110-14ikb_firmware | - |
| hp | 320-15ikbra_firmware | * |
| hp | lenovo_v720-14_firmware | * |
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | smart_assistant | * |
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | chassis_management_module_firmware | * |
In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | xclarity_integrator | * |
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | chassis_management_module_firmware | * |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovoemc_firmware | * |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovoemc_firmware | * |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovoemc_firmware | * |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | lenovoemc_firmware | * |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | storcenter_px2-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400r_firmware | 4.1.402.34662 |
| lenovo | px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px6-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2-dl_firmware | 4.1.402.34662 |
| lenovo | px4-300r_firmware | 4.1.402.34662 |
| lenovo | px2-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300d_firmware | 4.1.402.34662 |
| lenovo | px4-300d_firmware | 4.1.402.34662 |
| lenovo | px12-400r_firmware | 4.1.402.34662 |
| lenovo | ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-400r_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2_firmware | 4.1.402.34662 |
| lenovo | px6-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400d_firmware | 4.1.402.34662 |
| lenovo | ez_media_&_backup_center_firmware | 4.1.402.34662 |
| lenovo | ix2_firmware | 4.1.402.34662 |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | storcenter_px2-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400r_firmware | 4.1.402.34662 |
| lenovo | px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px6-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2-dl_firmware | 4.1.402.34662 |
| lenovo | px4-300r_firmware | 4.1.402.34662 |
| lenovo | px2-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300d_firmware | 4.1.402.34662 |
| lenovo | px4-300d_firmware | 4.1.402.34662 |
| lenovo | px12-400r_firmware | 4.1.402.34662 |
| lenovo | ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-400r_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2_firmware | 4.1.402.34662 |
| lenovo | px6-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400d_firmware | 4.1.402.34662 |
| lenovo | ez_media_&_backup_center_firmware | 4.1.402.34662 |
| lenovo | ix2_firmware | 4.1.402.34662 |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | storcenter_px2-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400r_firmware | 4.1.402.34662 |
| lenovo | px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px6-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2-dl_firmware | 4.1.402.34662 |
| lenovo | px4-300r_firmware | 4.1.402.34662 |
| lenovo | px2-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300d_firmware | 4.1.402.34662 |
| lenovo | px4-300d_firmware | 4.1.402.34662 |
| lenovo | px12-400r_firmware | 4.1.402.34662 |
| lenovo | ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-400r_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2_firmware | 4.1.402.34662 |
| lenovo | px6-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400d_firmware | 4.1.402.34662 |
| lenovo | ez_media_&_backup_center_firmware | 4.1.402.34662 |
| lenovo | ix2_firmware | 4.1.402.34662 |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | storcenter_px2-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400r_firmware | 4.1.402.34662 |
| lenovo | px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px6-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2-dl_firmware | 4.1.402.34662 |
| lenovo | px4-300r_firmware | 4.1.402.34662 |
| lenovo | px2-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300d_firmware | 4.1.402.34662 |
| lenovo | px4-300d_firmware | 4.1.402.34662 |
| lenovo | px12-400r_firmware | 4.1.402.34662 |
| lenovo | ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-400r_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2_firmware | 4.1.402.34662 |
| lenovo | px6-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400d_firmware | 4.1.402.34662 |
| lenovo | ez_media_&_backup_center_firmware | 4.1.402.34662 |
| lenovo | ix2_firmware | 4.1.402.34662 |
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | storcenter_px2-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400r_firmware | 4.1.402.34662 |
| lenovo | px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px6-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2-dl_firmware | 4.1.402.34662 |
| lenovo | px4-300r_firmware | 4.1.402.34662 |
| lenovo | px2-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px4-300d_firmware | 4.1.402.34662 |
| lenovo | px4-300d_firmware | 4.1.402.34662 |
| lenovo | px12-400r_firmware | 4.1.402.34662 |
| lenovo | ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix4-300d_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-450r_firmware | 4.1.402.34662 |
| lenovo | storcenter_px12-400r_firmware | 4.1.402.34662 |
| lenovo | storcenter_ix2_firmware | 4.1.402.34662 |
| lenovo | px6-300d_firmware | 4.1.402.34662 |
| lenovo | px4-400d_firmware | 4.1.402.34662 |
| lenovo | ez_media_&_backup_center_firmware | 4.1.402.34662 |
| lenovo | ix2_firmware | 4.1.402.34662 |
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | system_management_module_firmware | * |
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-276,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_x3250_m5_firmware | * |
| ibm | flex_system_x480_x6_firmware | * |
| lenovo | flex_system_x440_m4_firmware | * |
| ibm | bladecenter_hs23_firmware | * |
| ibm | system_x3650_m4_bd_firmware | * |
| lenovo | system_x3750_m4_firmware | * |
| ibm | system_x3300_m4_firmware | * |
| ibm | system_x3550_m4_firmware | * |
| ibm | flex_system_x280_x6_firmware | * |
| ibm | flex_system_x440_m4_firmware | * |
| ibm | idataplex_dx360_m4_water_cooled_firmware | * |
| ibm | idataplex_dx360_m4_firmware | * |
| ibm | flex_system_x880_x6_firmware | * |
| ibm | bladecenter_hs23e_firmware | * |
| ibm | system_x3100_m4_firmware | * |
| ibm | system_x3250_m4_firmware | * |
| ibm | flex_system_x220_m4_firmware | * |
| lenovo | flex_system_x240_m4_firmware | * |
| ibm | system_x3750_m4_firmware | * |
| ibm | system_x3850_x6_firmware | * |
| ibm | system_x3650_m4_hd_firmware | * |
| ibm | system_x3650_m4_firmware | * |
| ibm | system_x3100_m5_firmware | * |
| ibm | system_x3530_m4_firmware | * |
| ibm | flex_system_x240_m4_firmware | * |
| ibm | system_x3500_m4_firmware | * |
| ibm | flex_system_x222_m4_firmware | * |
| ibm | system_x3630_m4_firmware | * |
| ibm | system_x3950_x6_firmware | * |
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | thinkserver_rd640_firmware | * |
| lenovo | thinkserver_rd340_firmware | * |
| lenovo | thinkserver_rd440_firmware | * |
| lenovo | thinkserver_td340_firmware | * |