MidnightBSD

Advisories for lenovo

CVE-2007-1307 HIGH

Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
lenovo thinkpad x31
lenovo thinkpad t41
lenovo thinkpad x60
lenovo thinkpad t42p
lenovo thinkpad t60p
lenovo thinkpad r51
lenovo thinkpad t42
lenovo thinkpad t41p
lenovo thinkpad x60s
intel pro_1000_lan_adapter 135400
lenovo thinkpad x60_tablet
lenovo thinkpad r50e
lenovo thinkpad x32
lenovo thinkpad x40
lenovo thinkpad r50p
lenovo thinkpad r50
lenovo thinkpad t60
CVE-2007-2240 MEDIUM

The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
lenovo automated_solutions 1.0
lenovo access_support *
CVE-2007-2928 MEDIUM

Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
lenovo automated_solutions 1.0
lenovo access_support *
CVE-2007-2929 MEDIUM

The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
lenovo automated_solutions 1.0
lenovo access_support *
CVE-2008-3249 MEDIUM

The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
lenovo thinkvantage_system_update *
lenovo thinkvantage_system_update 3.13
CVE-2008-4589 HIGH

Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
lenovo resuce_and_recovery 4.20
lenovo resuce_and_recovery 4.20.0512
lenovo resuce_and_recovery 4.20.0511
CVE-2009-0655 MEDIUM

Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
lenovo veriface iii
CVE-2013-1361 HIGH

Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
lenovo thinkpad_bluetooth_with_enhanced_data_rate_software *
CVE-2014-1939 HIGH

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
google android 4.0.3
google android 4.0.4
lenovo shareit *
google android 4.0
google android 4.2
google android 4.1.2
google android *
google android 4.0.1
google android 4.2.1
google android 4.1
google android 4.3
google android 4.0.2
google android 4.2.2
CVE-2015-2219 HIGH

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo system_update *
CVE-2015-2233 HIGH

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-310,

Products Affected

Vendor Product Version
lenovo system_update *
CVE-2015-2234 MEDIUM

Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
lenovo system_update *
CVE-2015-3214 MEDIUM

The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
redhat enterprise_linux_compute_node_eus 7.4
redhat enterprise_linux_server_aus 7.7
redhat enterprise_linux_server 7.0
redhat enterprise_linux_compute_node_eus 7.7
lenovo emc_px12-450r_ivx *
redhat enterprise_linux_server_eus 7.4
arista eos 4.13
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_server_eus 7.6
redhat enterprise_linux_server_aus 7.6
arista eos 4.14
redhat enterprise_linux_for_scientific_computing 7.0
redhat enterprise_linux_server_update_services_for_sap_solutions 7.6
redhat virtualization 3.0
redhat enterprise_linux_server_eus 7.1
redhat enterprise_linux_for_power_big_endian 7.0
redhat enterprise_linux_server_aus 7.4
redhat enterprise_linux_server_update_services_for_sap_solutions 7.2
redhat openstack 6.0
redhat enterprise_linux_server_eus 7.5
redhat enterprise_linux_for_power_big_endian_eus 7.1_ppc64
qemu qemu *
arista eos 4.15
redhat enterprise_linux_compute_node_eus 7.2
redhat enterprise_linux_compute_node_eus 7.1
redhat enterprise_linux_server_aus 7.3
lenovo emc_px12-400r_ivx *
redhat enterprise_linux_for_power_big_endian_eus 7.2_ppc64
redhat enterprise_linux_for_power_big_endian_eus 7.4_ppc64
redhat enterprise_linux_server_update_services_for_sap_solutions 7.3
redhat enterprise_linux_server_tus 7.7
redhat enterprise_linux_for_power_big_endian_eus 7.5_ppc64
arista eos 4.12
redhat enterprise_linux_server_eus 7.3
redhat enterprise_linux_server_eus 7.7
redhat enterprise_linux_server_update_services_for_sap_solutions 7.7
redhat enterprise_linux_compute_node_eus 7.5
redhat enterprise_linux_for_power_big_endian_eus 7.3_ppc64
redhat openstack 5.0
debian debian_linux 7.0
debian debian_linux 8.0
redhat enterprise_linux_server_tus 7.3
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_workstation 7.0
redhat enterprise_linux_for_power_big_endian_eus 7.7_ppc64
redhat enterprise_linux_compute_node_eus 7.3
redhat enterprise_linux_for_power_big_endian_eus 7.6_ppc64
redhat enterprise_linux_compute_node_eus 7.6
linux linux_kernel *
redhat enterprise_linux_server_from_rhui 7.0
redhat enterprise_linux_server_update_services_for_sap_solutions 7.4
CVE-2015-3320 LOW

Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo usb_enhanced_performance_keyboard *
CVE-2015-3321 HIGH

Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo fingerprint_manager *
CVE-2015-3322 MEDIUM

Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
lenovo thinkserver_rd350_firmware *
lenovo thinkserver_rd450 *
lenovo thinkserver_rd550 *
lenovo thinkserver_rd450_firmware *
lenovo thinkserver_rd350 *
lenovo thinkserver_td350 *
lenovo thinkserver_rd650 *
lenovo thinkserver_td350_firmware *
lenovo thinkserver_rd550_firmware *
lenovo thinkserver_rd650_firmware *
CVE-2015-3323 MEDIUM

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo thinkserver_system_manager_baseboard_management_controller_firmware *
CVE-2015-3324 MEDIUM

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
lenovo thinkserver_system_manager_baseboard_management_controller_firmware 118.71532
CVE-2015-4596 MEDIUM

Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo mouse_suite *
CVE-2015-6971 HIGH

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
lenovo system_update *
CVE-2015-7817 HIGH

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-362,

Products Affected

Vendor Product Version
lenovo switch_center *
ibm system_networking_switch_center *
CVE-2015-7818 HIGH

The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo switch_center *
ibm system_networking_switch_center *
CVE-2015-7819 MEDIUM

The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
lenovo switch_center *
ibm system_networking_switch_center *
CVE-2015-7820 HIGH

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-362,

Products Affected

Vendor Product Version
lenovo switch_center *
ibm system_networking_switch_center *
CVE-2015-8108 MEDIUM

The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
lenovo emc_firmware 4.1.204.33661
CVE-2015-8109 MEDIUM

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
lenovo lenovo_system_update *
CVE-2015-8110 HIGH

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo lenovo_system_update *
CVE-2016-1344 HIGH

The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
cisco ios_xe 3.7s_3.7.4s
cisco ios_xe 3.11s_3.11.0s
cisco ios_xe 3.6s_3.6.0s
cisco ios_xe 3.4s_3.4.0as
cisco ios_xe 3.13s_3.13.2as
cisco ios_xe 3.6s_3.6.1s
cisco ios_xe 3.3sg_3.3.0sg
cisco ios_xe 3.4s_3.4.6s
cisco ios_xe 3.7s_3.7.1s
cisco ios_xe 3.15s_3.15.1s
cisco ios_xe 3.6e_3.6.2e
cisco ios_xe 3.10s_3.10.5s
cisco ios_xe 3.10s_3.10.2s
cisco ios_xe 3.14s_3.14.0s
cisco ios_xe 3.15s_3.15.1cs
cisco ios_xe 3.16s_3.16.0cs
cisco ios_xe 3.8s_3.8.1s
cisco ios_xe 3.4s_3.4.2s
cisco ios_xe 3.5e_3.5.3e
cisco ios_xe 3.5e_3.5.2e
cisco ios_xe 3.8e_3.8.0e
cisco ios_xe 3.4sg_3.4.4sg
cisco ios_xe 3.5s_3.5.2s
cisco ios_xe 3.3s_3.3.0s
cisco ios_xe 3.10s_3.10.1s
cisco ios_xe 3.16s_3.16.0s
cisco ios_xe 3.9s_3.9.0as
cisco ios_xe 3.4s_3.4.1s
cisco ios_xe 3.7s_3.7.3s
cisco ios_xe 3.10s_3.10.4s
cisco ios_xe 3.11s_3.11.3s
cisco ios_xe 3.9s_3.9.0s
cisco ios_xe 3.12s_3.12.1s
sun opensolaris snv_124
cisco ios_xe 3.5e_3.5.1e
cisco ios_xe 3.9s_3.9.1s
cisco ios_xe 3.10s_3.10.0s
cisco ios_xe 3.3sg_3.3.2sg
cisco ios_xe 3.7e_3.7.0e
cisco ios_xe 3.4s_3.4.3s
cisco ios_xe 3.5s_3.5.1s
cisco ios_xe 3.13s_3.13.0s
cisco ios_xe 3.8s_3.8.0s
cisco ios_xe 3.4s_3.4.4s
cisco ios_xe 3.6e_3.6.3e
cisco ios_xe 3.3xo_3.3.0xo
zzinc keymouse_firmware 3.08
cisco ios_xe 3.7e_3.7.2e
cisco ios_xe 3.4sg_3.4.3sg
cisco ios_xe 3.9s_3.9.2s
cisco ios_xe 3.9s_3.9.1as
cisco ios_xe 3.11s_3.11.2s
samsung x14j_firmware t-ms14jakucb-1102.5
cisco ios_xe 3.4sg_3.4.6sg
cisco ios_xe 3.3xo_3.3.2xo
cisco ios_xe 3.6e_3.6.2ae
cisco ios_xe 3.10s_3.10.6s
cisco ios_xe 3.11s_3.11.1s
cisco ios_xe 3.17s_3.17.0s
cisco ios_xe 3.15s_3.15.2s
cisco ios_xe 3.12s_3.12.4s
cisco ios_xe 3.14s_3.14.3s
cisco ios_xe 3.4sg_3.4.0sg
cisco ios_xe 3.5s_3.5.0s
cisco ios_xe 3.15s_3.15.0s
cisco ios_xe 3.10s_3.10.1xbs
cisco ios_xe 3.7s_3.7.5s
cisco ios_xe 3.7s_3.7.6s
cisco ios_xe 3.4sg_3.4.2sg
cisco ios_xe 3.13s_3.13.2s
cisco ios_xe 3.16s_3.16.1as
cisco ios_xe 3.11s_3.11.4s
cisco ios_xe 3.12s_3.12.2s
cisco ios_xe 3.4s_3.4.5s
cisco ios_xe 3.16s_3.16.1s
lenovo thinkcentre_e75s_firmware *
cisco ios_xe 3.14s_3.14.1s
zyxel gs1900-10hp_firmware *
cisco ios_xe 3.7s_3.7.2ts
cisco ios_xe 3.8e_3.8.1e
cisco ios_xe 3.3s_3.3.2s
cisco ios_xe 3.4sg_3.4.5sg
cisco ios_xe 3.7e_3.7.1e
cisco ios_xe 3.6e_3.6.0e
cisco ios_xe 3.10s_3.10.3s
cisco ios_xe 3.7s_3.7.2s
cisco ios_xe 3.12s_3.12.3s
cisco ios_xe 3.13s_3.13.4s
cisco ios_xe 3.13s_3.13.1s
cisco ios_xe 3.6s_3.6.2s
cisco ios_xe 3.7e_3.7.3e
cisco ios_xe 3.14s_3.14.2s
cisco ios_xe 3.3xo_3.3.1xo
cisco ios_xe 3.3sg_3.3.1sg
cisco ios_xe 3.4sg_3.4.1sg
cisco ios_xe 3.4sg_3.4.7sg
cisco ios_xe 3.13s_3.13.0as
cisco ios_xe 3.7s_3.7.7s
cisco ios_xe 3.13s_3.13.3s
cisco ios_xe 3.12s_3.12.0s
cisco ios_xe 3.3s_3.3.1s
cisco ios_xe 3.7s_3.7.4as
netgear jr6150_firmware *
cisco ios_xe 3.4s_3.4.0s
cisco ios_xe 3.6e_3.6.1e
cisco ios_xe 3.5e_3.5.0e
cisco ios_xe 3.7s_3.7.0s
cisco ios_xe 3.8s_3.8.2s
CVE-2016-1350 HIGH

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
zyxel gs1900-10hp_firmware *
cisco ios_xe 3.9.0as
cisco ios_xe 3.10.1xbs
cisco ios_xe 3.8.2s
cisco ios_xe 3.9.1as
cisco ios_xe 3.10.2s
samsung x14j_firmware t-ms14jakucb-1102.5
cisco ios_xe 3.9.2s
cisco ios_xe 3.8.0s
cisco ios_xe 3.10.1s
cisco ios_xe 3.8.1s
cisco ios_xe 3.9.1s
sun opensolaris snv_124
cisco ios_xe 3.9.0s
zzinc keymouse_firmware 3.08
lenovo thinkcentre_e75s_firmware *
cisco ios_xe 3.11.0s
cisco ios_xe 3.10.0s
CVE-2016-1489 MEDIUM

Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-254,

Products Affected

Vendor Product Version
lenovo shareit *
CVE-2016-1490 LOW

The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo shareit *
CVE-2016-1491 MEDIUM

The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
lenovo shareit *
CVE-2016-1492 LOW

The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

CVSS 2.0

Severity: LOW

Problem Type: CWE-284,

Products Affected

Vendor Product Version
lenovo shareit 3.0.18_ww
CVE-2016-1876 HIGH

The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo solution_center *
CVE-2016-2393 HIGH

Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo fingerprint_manager *
lenovo touch_fingerprint *
CVE-2016-3944 HIGH

UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo accelerator_application -
CVE-2016-4782 HIGH

Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent scheme URL attack."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo shareit 3.5.98_ww
CVE-2016-4783 MEDIUM

Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
lenovo shareit 3.5.98_ww
CVE-2016-5247 HIGH

The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass the Secure Boot protection mechanism by leveraging an AMI test key.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-254,

Products Affected

Vendor Product Version
lenovo bios -
CVE-2016-5248 LOW

The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo solution_center *
CVE-2016-5249 HIGH

Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Services.SystemService StartProxy command with a named pipe created in advance and crafted .NET assembly.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo solution_center *
CVE-2016-5729 MEDIUM

Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 1.5 6.0

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo bios_efi_driver -
CVE-2016-6257 LOW

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 2.8 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
dell km632_firmware -
dell km714_firmware *
lenovo ultraslim_firmware -
amazonbasics firmware -
logitech unifying_firmware *
CVE-2016-8106 MEDIUM

A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo converged_hx5510_appliance 5.05
lenovo system_x3750_m4 5.05
lenovo thinkagile_cx2200 5.05
hp ethernet_10gb_2-port_562flr-sfp+ *
lenovo thinkserver_rd450 5.05
lenovo thinkserver_sd350 5.05
lenovo system_x3550_m5 5.05
intel ethernet_controller_xl710_firmware *
lenovo converged_hx5500_appliance 5.05
lenovo thinkserver_td350 5.05
lenovo system_x3950_x6 5.05
hp ethernet_10gb_4-port_563sfp+ *
lenovo thinkserver_rd650 5.05
hp proliant_xl260a_g9_server *
lenovo system_x3650_m5 5.05
lenovo thinkserver_rd550 5.05
intel ethernet_controller_x710_firmware *
hp ethernet_10gb_2-port_562sfp+ *
lenovo nextscale_nx360_m5 5.05
lenovo system_x3500_m5 5.05
lenovo converged_hx_series 5.05
lenovo converged_hx7500_appliance 5.05
lenovo thinkagile_cx4200 5.05
lenovo converged_hx7510_appliance 5.05
lenovo thinkserver_rd350 5.05
lenovo thinkagile_cx4600 5.05
lenovo system_x3250_m5 5.05
lenovo system_x3850_x6 5.05
CVE-2016-8221 LOW

Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are used internally by LXCA code.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2016-8222 MEDIUM

A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
lenovo thinkpad_w540_bios -
lenovo thinkpad_e465_bios -
lenovo thinkpad_t440_bios -
lenovo thinkpad_l540_bios -
lenovo thinkpad_t460_bios -
lenovo thinkpad_e550_bios -
lenovo thinkpad_yoga_14_460_s3_bios -
lenovo thinkpad_x240s_bios -
lenovo thinkpad_yoga_11e_beema_bios -
lenovo thinkpad_x250_broadwell_bios -
lenovo thinkpad_11e_skylake_bios -
lenovo thinkpad_x260_bios -
lenovo thinkpad_p50_bios -
lenovo thinkpad_yoga_11e_braswell_bios -
lenovo thinkpad_edge_e545_bios -
lenovo thinkpad_x1_carbon_20bx_bios -
lenovo thinkpad_yoga_11e_bios -
lenovo thinkpad_p70_bios -
lenovo thinkpad_t460p_bios -
lenovo thinkpad_l560_bios -
lenovo thinkpad_t450s_bios -
lenovo thinkpad_l450_bios -
lenovo thinkpad_t550_bios -
lenovo thinkpad_l440_bios -
lenovo thinkpad_t560_bios -
lenovo thinkpad_t460s_bios -
lenovo thinkpad_tablet_8_bios -
lenovo thinkpad_x250_sharkbay_bios -
lenovo thinkpad_t540_bios -
lenovo thinkpad_s3_yoga_14_bios -
lenovo thinkpad_e460_bios -
lenovo thinkpad_yoga_260_s1_bios -
lenovo thinkpad_11e_broadwell_bios -
lenovo thinkpad_helix_20ch_bios -
lenovo thinkpad_p50s_bios -
lenovo thinkpad_11e_braswell_bios -
lenovo thinkpad_helix_20cg_bios -
lenovo thinkpad_x1_carbon_bios -
lenovo thinkpad_e560_bios -
lenovo thinkpad_s1_yoga_12_bios -
lenovo thinkpad_x1_yoga_bios -
lenovo thinkpad_x140e_amd_bios -
lenovo thinkpad_tablet_10_bios -
lenovo thinkpad_13e_bios -
lenovo thinkpad_e450c_bios -
lenovo thinkpad_l460_bios -
lenovo thinkpad_e555_bios -
lenovo thinkpad_e450_bios -
lenovo thinkpad_s5_e560p_bios -
lenovo thinkpad_t440s_bios -
lenovo thinkpad_t540p_bios -
lenovo thinkpad_t440p_bios -
lenovo thinkpad_x1_tablet_bios -
lenovo thinkpad_edge_e445_bios -
lenovo thinkpad_11e_beema_bios -
lenovo thinkpad_yoga_11e_broadwell_bios -
lenovo thinkpad_edge_e540_bios -
lenovo thinkpad_s5_yoga_15_bios -
lenovo thinkpad_x1_carbon_20ax_bios -
lenovo thinkpad_e455_bios -
lenovo thinkpad_t450_bios -
lenovo thinkpad_e565_bios -
lenovo thinkpad_s540_bios -
lenovo thinkpad_w550s_bios -
lenovo thinkpad_x240_bios -
lenovo thinkpad_e550c_bios -
lenovo thinkpad_edge_e440_bios -
lenovo thinkpad_w541_bios -
lenovo thinkpad_s1_yoga_vpro_bios -
lenovo thinkpad_s3_s440_bios -
lenovo thinkpad_t440u_bios -
lenovo thinkpad_yoga_11e_skylake_bios -
lenovo thinkpad_10_ella_2_bios -
lenovo thinkpad_s1_yoga_non_vpro_bios -
CVE-2016-8223 HIGH

During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
lenovo system_interface_foundation *
CVE-2016-8224 MEDIUM

A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
lenovo notebook_ideapad_510s_12isk_bios -
lenovo notebook_e31_80_bios -
lenovo notebook_k41_80_bios -
lenovo notebook_ideapad_300_15isk_bios -
lenovo notebook_ideapad_300_15ibr_bios -
lenovo notebook_yoga_900s_12isk_bios -
lenovo notebook_ideapad_300_17isk_bios -
lenovo notebook_ideapad_300_14ibr_bios -
lenovo thinkserver_ts150_bios -
lenovo notebook_miix_710_12ikb_bios -
lenovo notebook_e40_80_bios -
lenovo notebook_ideapad_300_14isk_bios -
lenovo notebook_yoga_510_14isk_bios -
lenovo notebook_g40_80_bios -
lenovo notebook_e41_80_bios -
lenovo notebook_xiaoxin_air_12_bios -
lenovo notebook_yoga_510_15isk_bios -
lenovo thinkserver_ts450_bios -
lenovo notebook_yoga_710_11isk_bios -
lenovo notebook_110_14ibr_bios -
lenovo notebook_110_15ibr_bios -
lenovo notebook_g50_80_touch_bios -
lenovo notebook_yoga_900_13isk_bios -
lenovo bios -
lenovo notebook_g50_80_bios -
lenovo notebook_b70_80_bios -
lenovo notebook_yoga_710_11ikb_bios -
lenovo notebook_e51_80_bios -
lenovo notebook_k21_80_bios -
CVE-2016-8225 MEDIUM

Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-428,

Products Affected

Vendor Product Version
lenovo edge_keyboard_driver *
lenovo slim_usb_keyboard_driver *
CVE-2016-8226 MEDIUM

The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-19,

Products Affected

Vendor Product Version
lenovo flex_system_x280_m6_bios -
lenovo system_x3550_m5_bios -
lenovo flex_system_x240_m5_bios -
lenovo system_x3650_m5_bios -
lenovo flex_system_x880_x6_bios -
lenovo system_x3500_m5_bios -
lenovo flex_system_x480_x6_bios -
lenovo nextscale_nx360_m5_bios -
lenovo system_x3250_m6_bios -
lenovo system_x3950_x6_bios -
lenovo system_x3850_x6_bios -
CVE-2016-8227 HIGH

Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local users to execute code with elevated privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
lenovo transition -
CVE-2016-8228 HIGH

In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo lenovo_service_bridge -
CVE-2016-8229 MEDIUM

A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
lenovo lenovo_service_bridge -
CVE-2016-8230 MEDIUM

In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo lenovo_service_bridge -
CVE-2016-8231 MEDIUM

In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
lenovo lenovo_service_bridge -
CVE-2016-8233 MEDIUM

Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2016-8235 HIGH

Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo customer_care_software_development_kit *
CVE-2016-8236 MEDIUM

Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
lenovo thinkserver_firmware *
CVE-2016-8237 HIGH

Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
lenovo updates -
CVE-2017-17833 HIGH

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
canonical ubuntu_linux 14.04
redhat enterprise_linux_desktop 6.0
lenovo thinkserver_rd350g_firmware -
redhat enterprise_linux_server 7.0
lenovo thinksystem_sr630_firmware -
lenovo thinkserver_rd450_firmware *
lenovo xclarity_administrator *
lenovo cmm *
openslp openslp 1.0.2
lenovo thinkserver_td350_firmware *
lenovo thinksystem_hr630x_firmware -
lenovo thinkserver_rd450x_firmware -
openslp openslp 1.1.0
lenovo thinkserver_sd350_firmware -
redhat enterprise_linux_desktop 7.0
lenovo storage_n4610_firmware *
redhat enterprise_linux_server 6.0
lenovo thinkserver_rd350_firmware *
lenovo thinkserver_rd540_firmware *
lenovo thinksystem_hr650x_firmware -
lenovo thinkserver_rd340_firmware *
lenovo thinkserver_rd440_firmware *
lenovo fan_power_controller *
lenovo storage_n3310_firmware *
lenovo imm1 *
redhat enterprise_linux_workstation 6.0
lenovo thinkserver_rd650_firmware *
redhat enterprise_linux_server_tus 7.6
lenovo thinkserver_rd640_firmware *
redhat enterprise_linux_server_eus 7.6
lenovo thinkserver_rs160_firmware *
redhat enterprise_linux_server_aus 7.6
canonical ubuntu_linux 16.04
lenovo thinkserver_rd350x_firmware -
lenovo thinkserver_td340_firmware *
lenovo flex_system_fc3171_8gb_san_switch_firmware *
lenovo bm_nextscale_fan_power_controller *
lenovo thinkserver_rq750_firmware *
lenovo thinkserver_ts460_firmware *
debian debian_linux 7.0
redhat enterprise_linux_workstation 7.0
lenovo thinkserver_rd550_firmware *
lenovo imm2 *
redhat enterprise_linux_server_eus 7.5
CVE-2017-3740 MEDIUM

In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo active_protection_system 1.01b
lenovo active_protection_system 1.40
lenovo active_protection_system 1.77.0.20
lenovo active_protection_system 1.82.0.06
lenovo active_protection_system 1.76
lenovo active_protection_system 1.51
lenovo active_protection_system 1.77.0.8
lenovo active_protection_system 1.78.0.11
lenovo active_protection_system 1.80.3.00
lenovo active_protection_system 1.80.8.00
lenovo active_protection_system 1.71
lenovo active_protection_system 1.75
lenovo active_protection_system 1.77.0.11
lenovo active_protection_system 1.31
lenovo active_protection_system 1.73
lenovo active_protection_system 1.77.0.9
lenovo active_protection_system 1.20b
lenovo active_protection_system 1.23
lenovo active_protection_system 1.82.0.03
lenovo active_protection_system 1.33b
lenovo active_protection_system 1.82.0.10
lenovo active_protection_system 1.52
lenovo active_protection_system 1.54
lenovo active_protection_system 1.22
lenovo active_protection_system 1.62
lenovo active_protection_system 1.81.0.08
lenovo active_protection_system 1.70
lenovo active_protection_system 1.80.1.00
lenovo active_protection_system 1.32
lenovo active_protection_system 1.41
lenovo active_protection_system 1.64
lenovo active_protection_system 1.72
lenovo active_protection_system 1.63
lenovo active_protection_system 1.61
lenovo active_protection_system 1.00b
lenovo active_protection_system 1.21
lenovo active_protection_system 1.30b
lenovo active_protection_system 1.80.11.00
lenovo active_protection_system 1.79.0.03
lenovo active_protection_system 1.77.0.5
lenovo active_protection_system 1.77.0.26
lenovo active_protection_system 1.78.0.10
lenovo active_protection_system 1.50
lenovo active_protection_system 1.34
lenovo active_protection_system 1.53
lenovo active_protection_system 1.78.0.09
lenovo active_protection_system 1.74
lenovo active_protection_system 1.77.0.7
lenovo active_protection_system 1.82.0.07
CVE-2017-3741 LOW

In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo power_management 1.67.12.23
lenovo power_management 1.67.12.19
CVE-2017-3742 LOW

In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents could connect to the Connect2 hotspot and see the contents of files while they are being transferred between the two systems.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo connect2 *
CVE-2017-3743 LOW

If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.

CVSS 2.0

Severity: LOW

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo advanced_settings_utility *
lenovo toolscenter_dynamic_system_analysis *
lenovo updatexpress_system_pack_installer *
CVE-2017-3744 MEDIUM

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
lenovo integrated_management_module_firmware *
ibm integrated_management_module_firmware *
CVE-2017-3745 LOW

In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.

CVSS 2.0

Severity: LOW

Problem Type: CWE-287,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2017-3746 HIGH

ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative or system level privileges.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo thinkpad_usb_3.0_ethernet_adapter_driver -
CVE-2017-3747 LOW

Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo nerve_center -
CVE-2017-3751 HIGH

An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-428,

Products Affected

Vendor Product Version
lenovo thinkpad_compact_usb_keyboard_driver -
CVE-2017-3752 MEDIUM

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo fabric_en4093r_10gb_firmware *
lenovo g8272_firmware *
ibm virtual_fabric_10gb *
lenovo g8264_firmware *
ibm g8124_firmware *
ibm g8264cs_firmware *
lenovo g8332_firmware *
ibm fabric_cn4093_10gb_firmware *
lenovo g8052_firmware *
ibm g8316_firmware *
ibm fabric_en4093/en4093r_10gb_firmware *
ibm en2092_1gb_firmware *
ibm 1g_l2-7_slb *
ibm layer_2/3_copper_firmware *
ibm g8332_firmware *
lenovo g8264cs_firmware *
ibm g8052_firmware *
ibm 1:10g_firmware *
ibm g8264t_firmware *
ibm g8264_firmware *
lenovo si4091_firmware *
ibm g8124e_firmware *
lenovo fabric_cn4093_10gb_firmware *
lenovo g8296_firmware *
lenovo g8124e_firmware *
CVE-2017-3753 HIGH

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
lenovo thinkstation_p300_firmware fbktc6a
lenovo thinkcentre_m4600t/s_firmware m05kt54a
lenovo thinkcentre_m6600t/s_firmware fwkt39a
lenovo thinkcentre_m72e_firmware f1kt71a
lenovo thinkserver_td340_firmware a3tsb5a
lenovo thinkcentre_m79_firmware m0lkt12a
lenovo thinkserver_rd340_firmware -
lenovo thinkserver_ts450_firmware -
lenovo thinkcentre_m6500t/s_firmware fbktc5a
lenovo yangtian_me/we_h110_firmware m05kt61a
lenovo thinkcentre_m8300z_firmware fvkt42a
lenovo thinkcentre_m9550z_firmware fukt44a
lenovo yangtian_mc_carrizo-l_firmware -
lenovo thinkstation_p700_firmware a5kt86a
lenovo thinkserver_rd440_firmware a0tsb5a
lenovo thinkcentre_m800z_firmware fvkt42a
lenovo thinkserver_rd640_firmware a1tsb5a
lenovo thinkcentre_m700_firmware m05kt54a
lenovo thinkstation_p320_firmware -
lenovo thinkstation_d30_(4353)_firmware a3kt57a
lenovo yangtian_s800_firmware ffkt43a
lenovo thinkstation_e32_firmware fbktc6a
lenovo thinkcentre_e75_t/s_firmware -
lenovo ideacentre_300s-11ish_firmware -
lenovo thinkstation_p510_firmware -
lenovo thinkcentre_m4500q_firmware fhkt66a
lenovo yangtian_mc_h110_firmware m05kt61a
lenovo thinkcentre_m900z_firmware fukt39a
lenovo thinkcentre_m700z_firmware fvkt48a
lenovo thinkcentre_m83_firmware fbktcga
lenovo ideacentre_510s-23isu_firmware o2ekt24a
lenovo thinkstation_p710_firmware -
lenovo yangtian_s3040_firmware fgkt49a
lenovo thinkcentre_m8600t/s_firmware fwkt39a
lenovo s500_firmware m0kkt24a
lenovo yangtian_afh81_firmware fckt80a
lenovo thinkcentre_e73z_(aio)_firmware fgkt49a
lenovo thinkcentre_m4500t/s_firmware fckt78a
lenovo yangtian_afq150_firmware fwkt57a
lenovo ideacentre_700_firmware -
lenovo thinkcentre_m7300z_firmware fvkt42a
lenovo thinkcentre_m73z_(aio)_firmware fgkt46a
lenovo thinkcentre_e79_firmware m0lkt12a
lenovo thinkcentre_m900_firmware fwkt39a
lenovo thinkcentre_m7200z_firmware fgkt46a
lenovo thinkstation_c30_(1136)_firmware a1kt57a
lenovo thinkcentre_m910t/s_firmware -
lenovo thinkserver_rd540_firmware a1tsb5a
lenovo thinkcentre_m4500k_firmware fckt78a
lenovo thinkserver_rs140_firmware fbkt91c
lenovo thinkcentre_e93z_(aio)_firmware ffkt43a
lenovo thinkstation_p900_firmware a6kt86a
lenovo thinkcentre_m610_firmware -
lenovo thinkstation_p410_firmware -
lenovo thinkcentre_e74s_firmware m05kt54a
lenovo thinkstation_p500_firmware a4kt86a
lenovo 63_firmware fckt78a
lenovo thinkcentre_m710t/s_firmware -
lenovo thinkcentre_m9500z_firmware fukt44a
lenovo thinkcentre_m92p_firmware 9skt95a
lenovo thinkcentre_e74z_firmware fvkt48a
lenovo thinkstation_p310_firmware fwkt57a
lenovo v320-15iap_firmware -
lenovo thinkserver_rq750_firmware 7.05
lenovo yangtian_mc_godavari_firmware m0lkt13a
lenovo ideacentre_510s-08ish_firmware -
lenovo thinkcentre_m810z_firmware -
lenovo thinkcentre_e73_firmware fckt78a
lenovo thinkstation_d30_(4354)_firmware a3kt57a
lenovo m4500_id_firmware fckt78a
lenovo thinkstation_c30_(1137)_firmware a1kt57a
lenovo thinkcentre_e73s_firmware fckt78a
lenovo yangtian_afh110_firmware m05kt73a
lenovo thinkcentre_m8200z_firmware fgkt46a
lenovo thinkcentre_m93_firmware fbktc5a
lenovo thinkcentre_m73p_firmware fbktc5a
lenovo thinkcentre_m800_firmware fwkt39a
lenovo yangtian_mc_h81_firmware fckt80a
lenovo s200z_firmware m09kt33a
lenovo thinkcentre_m8250z_firmware fgkt46a
lenovo thinkcentre_m910x_firmware -
lenovo thinkcentre_m600_firmware m00kt44a
lenovo thinkcentre_edge_62z_firmware f8kt40a
lenovo thinkcentre_e74_firmware m05kt54a
lenovo thinkserver_ts250_firmware -
lenovo h50-30g_firmware fckt78a
lenovo thinkcentre_m8500t/s_firmware fbktc5a
lenovo thinkstation_s30_(4351)_firmware a2kt54a
lenovo thinkserver_ts550_firmware -
lenovo thinkcentre_m83z_(aio)_firmware fvkt42a
lenovo thinkstation_s30_(4352)_firmware a2kt54a
lenovo m4500_firmware fckt78a
lenovo thinkserver_ts150_firmware fbktc3a
lenovo thinkcentre_x1_aio_firmware m0hkt32a
lenovo thinkserver_ts140_firmware fbktc3a
lenovo thinkcentre_m715q_firmware -
lenovo thinkcentre_m92_firmware 9skt95a
lenovo thinkcentre_e93_firmware fbktc5a
lenovo thinkcentre_m73_firmware fckt78a
lenovo thinkcentre_m7250z_firmware fgkt46a
lenovo thinkserver_ts240_firmware fbktc3a
lenovo m4550_id_firmware fckt78a
lenovo thinkcentre_m93p_firmware fbktc5a
lenovo thinkstation_e31_firmware 9skt97a
lenovo thinkcentre_m910q_firmware -
lenovo thinkcentre_m6600_firmware fwkt39a
lenovo yangtian_mf/wf_h81_firmware fckt80a
lenovo thinkcentre_m8350z_firmware fvkt42a
lenovo thinkstation_p910_firmware -
lenovo thinkcentre_m6600q_firmware fwkt39a
lenovo ideacentre_300-20ish_firmware -
CVE-2017-3754 HIGH

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo bios -
CVE-2017-3756 HIGH

A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo thinkpad_edge_e540 -
lenovo thinkpad_t560 -
lenovo thinkpad_t460_bios -
lenovo thinkpad_e550_bios -
lenovo thinkpad_yoga_14_460_s3_bios -
lenovo thinkpad_e450 -
lenovo thinkpad_tablet_10 -
lenovo thinkpad_yoga_11e_beema_bios -
lenovo thinkpad_s3_yoga_14 -
lenovo thinkpad_x250_broadwell_bios -
lenovo thinkpad_e450c -
lenovo thinkpad_11e_skylake_bios -
lenovo thinkpad_l560 -
lenovo thinkpad_yoga_11e_bios -
lenovo thinkpad_s1_yoga_vpro -
lenovo thinkpad_t450s_bios -
lenovo thinkpad_l450_bios -
lenovo thinkpad_l440 -
lenovo thinkpad_edge_e440 -
lenovo thinkpad_s1_yoga_12 -
lenovo thinkpad_t560_bios -
lenovo thinkpad_s5_e560p -
lenovo thinkpad_t440u -
lenovo thinkpad_tablet_8_bios -
lenovo thinkpad_s3_s440 -
lenovo thinkpad_11e_broadwell_bios -
lenovo thinkpad_x1_tablet -
lenovo thinkpad_p50 -
lenovo thinkpad_p50s_bios -
lenovo thinkpad_w540 -
lenovo thinkpad_x250_broadwell -
lenovo thinkpad_helix_20cg_bios -
lenovo thinkpad_x1_carbon_bios -
lenovo thinkpad_x1_yoga_bios -
lenovo thinkpad_helix_20cg -
lenovo thinkpad_x140e_amd_bios -
lenovo thinkpad_tablet_10_bios -
lenovo thinkpad_yoga_14_460_s3 -
lenovo thinkpad_t540p -
lenovo thinkpad_e450_bios -
lenovo thinkpad_e550 -
lenovo thinkpad_s5_yoga_15 -
lenovo thinkpad_t460p -
lenovo thinkpad_edge_e445 -
lenovo thinkpad_p50s -
lenovo thinkpad_x1_tablet_bios -
lenovo thinkpad_x260 -
lenovo thinkpad_11e_beema_bios -
lenovo thinkpad_yoga_11e_broadwell_bios -
lenovo thinkpad_p70 -
lenovo thinkpad_edge_e540_bios -
lenovo thinkpad_s5_yoga_15_bios -
lenovo thinkpad_t460s -
lenovo thinkpad_tablet_8 -
lenovo thinkpad_t450_bios -
lenovo thinkpad_t540 -
lenovo thinkpad_w541 -
lenovo thinkpad_10_ella_2 -
lenovo thinkpad_s540_bios -
lenovo thinkpad_x1_carbon_20bx -
lenovo thinkpad_yoga_11e_broadwell -
lenovo thinkpad_x240_bios -
lenovo thinkpad_e465 -
lenovo thinkpad_11e_skylake -
lenovo thinkpad_s540 -
lenovo thinkpad_x1_carbon_20ax -
lenovo thinkpad_l460 -
lenovo thinkpad_e455 -
lenovo thinkpad_t440u_bios -
lenovo thinkpad_yoga_11e_skylake_bios -
lenovo thinkpad_s1_yoga_non_vpro_bios -
lenovo thinkpad_t440p -
lenovo thinkpad_w540_bios -
lenovo thinkpad_e465_bios -
lenovo thinkpad_t440_bios -
lenovo thinkpad_l540_bios -
lenovo thinkpad_x240s_bios -
lenovo thinkpad_yoga_11e_skylake -
lenovo thinkpad_x260_bios -
lenovo thinkpad_yoga_11e -
lenovo thinkpad_p50_bios -
lenovo thinkpad_yoga_11e_braswell_bios -
lenovo thinkpad_edge_e545_bios -
lenovo thinkpad_x1_carbon_20bx_bios -
lenovo thinkpad_p70_bios -
lenovo thinkpad_t460p_bios -
lenovo thinkpad_t550 -
lenovo thinkpad_l560_bios -
lenovo thinkpad_11e_beema -
lenovo thinkpad_e565 -
lenovo thinkpad_13e -
lenovo thinkpad_x240s -
lenovo thinkpad_yoga_11e_braswell -
lenovo thinkpad_t550_bios -
lenovo thinkpad_l440_bios -
lenovo thinkpad_t460s_bios -
lenovo thinkpad_t450 -
lenovo thinkpad_w550s -
lenovo thinkpad_x250_sharkbay_bios -
lenovo thinkpad_x240 -
lenovo thinkpad_t540_bios -
lenovo thinkpad_s3_yoga_14_bios -
lenovo thinkpad_e460_bios -
lenovo thinkpad_yoga_260_s1_bios -
lenovo thinkpad_l540 -
lenovo thinkpad_11e_braswell -
lenovo thinkpad_x140e_amd -
lenovo thinkpad_helix_20ch_bios -
lenovo thinkpad_11e_braswell_bios -
lenovo thinkpad_e560_bios -
lenovo thinkpad_s1_yoga_12_bios -
lenovo thinkpad_e555 -
lenovo thinkpad_11e_broadwell -
lenovo thinkpad_13e_bios -
lenovo thinkpad_e450c_bios -
lenovo thinkpad_edge_e545 -
lenovo thinkpad_l460_bios -
lenovo thinkpad_t450s -
lenovo thinkpad_e555_bios -
lenovo thinkpad_l450 -
lenovo thinkpad_helix_20ch -
lenovo thinkpad_yoga_11e_beema -
lenovo thinkpad_s5_e560p_bios -
lenovo thinkpad_t440s_bios -
lenovo thinkpad_t540p_bios -
lenovo thinkpad_t440p_bios -
lenovo thinkpad_e560 -
lenovo thinkpad_x1_yoga -
lenovo thinkpad_x250_sharkbay -
lenovo thinkpad_edge_e445_bios -
lenovo thinkpad_x1_carbon -
lenovo thinkpad_t440 -
lenovo thinkpad_x1_carbon_20ax_bios -
lenovo thinkpad_yoga_260_s1 -
lenovo thinkpad_e455_bios -
lenovo thinkpad_e565_bios -
lenovo thinkpad_w550s_bios -
lenovo thinkpad_e460 -
lenovo thinkpad_t440s -
lenovo thinkpad_t460 -
lenovo thinkpad_e550c -
lenovo thinkpad_e550c_bios -
lenovo thinkpad_edge_e440_bios -
lenovo thinkpad_s1_yoga_non_vpro -
lenovo thinkpad_w541_bios -
lenovo thinkpad_s1_yoga_vpro_bios -
lenovo thinkpad_s3_s440_bios -
lenovo thinkpad_10_ella_2_bios -
CVE-2017-3758 HIGH

Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo service_framework -
CVE-2017-3759 MEDIUM

The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo service_framework -
CVE-2017-3760 MEDIUM

The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-354,CWE-522,

Products Affected

Vendor Product Version
lenovo service_framework -
CVE-2017-3761 HIGH

The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo service_framework -
CVE-2017-3762 HIGH

Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
lenovo fingerprint_manager_pro *
CVE-2017-3763 LOW

An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2017-3764 MEDIUM

A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2017-3765 MEDIUM

In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
lenovo enterprise_network_operating_system *
CVE-2017-3770 MEDIUM

Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2017-3771 MEDIUM

System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo thinkcentre_m710t_firmware *
lenovo thinkcentre_m710s_firmware *
lenovo aio_e95_firmware *
CVE-2017-3774 HIGH

A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
lenovo integrated_management_module_2 *
CVE-2017-3775 MEDIUM

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
lenovo system_x3650_m5_bios *
lenovo system_x3500_m5_bios *
lenovo flex_system_x880_bios *
lenovo nextscale_nx360_m5_bios *
lenovo flex_system_x480_x6_bios *
lenovo system_x3550_m5_bios *
lenovo system_x3250_m6_bios *
lenovo flex_system_x240_m5_bios *
lenovo system_x3850_x6_bios *
lenovo flex_system_x280_x6_bios *
lenovo system_x3950_x6_bios *
CVE-2017-3776 MEDIUM

Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo lenovo_help *
CVE-2017-5638 HIGH

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-755,CWE-755,

Products Affected

Vendor Product Version
apache struts *
hp server_automation 10.2.0
oracle weblogic_server 12.1.3.0.0
lenovo storage_v5030_firmware 7.7.1.6
hp server_automation 10.0.0
ibm storwize_v7000_firmware 7.7.1.6
hp server_automation 10.1.0
arubanetworks clearpass_policy_manager *
lenovo storage_v5030_firmware 7.8.1.0
hp server_automation 10.5.0
oracle weblogic_server 10.3.6.0.0
ibm storwize_v3500_firmware 7.8.1.0
ibm storwize_v3500_firmware 7.7.1.6
ibm storwize_v5000_firmware 7.7.1.6
ibm storwize_v7000_firmware 7.8.1.0
hp server_automation 9.1.0
netapp oncommand_balance -
oracle weblogic_server 12.2.1.2.0
oracle weblogic_server 12.2.1.1.0
ibm storwize_v5000_firmware 7.8.1.0
CVE-2018-12169 MEDIUM

Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
intel core_i3 4100u
intel core_i7 8809g
intel core_i5 4210y
intel core_i7 4600u
intel core_i5 4400e
intel core_i7 4760hq
intel core_i5 4402e
intel core_i5 4690k
intel core_i7 6567u
intel core_i3 6300
intel core_i7 8709g
intel core_i5 4210m
intel core_i5 8350u
intel core_i3 8100
intel core_i5 8259u
lenovo thinkpad_t470 -
intel core_i5 8500
intel core_i5 4310m
intel core_i7 4510u
lenovo thinkpad_t470s -
intel core_i7 6920hq
intel core_i5 8200y
intel core_i5 4402ec
intel core_i7 4610m
intel core_i5 7400
intel core_i7 8650u
intel core_i7 4702hq
intel core_i3 4170t
intel core_i5 5250u
intel core_i7 4750hq
intel core_i5 7300hq
intel core_i5 7400t
intel core_i7 4790s
intel core_i5 4200m
intel core_i5 8300h
intel core_i7 4722hq
lenovo thinkpad_x1_tablet -
intel core_i7 4610y
lenovo thinkpad_p51 -
lenovo thinkpad_t470p -
intel core_i5 4570s
intel core_i5 8269u
intel core_i3 6102e
intel core_i5 6350hq
intel core_i7 5550u
lenovo thinkpad_x380_yoga -
intel core_i7 4770hq
intel core_i5 7500t
intel core_i3 4160t
intel core_i7 4790k
intel core_i3 4360t
intel core_i5 4330m
intel core_i7 8700b
intel core_i7 6500u
intel core_i3 8130u
lenovo thinkpad_t25 -
intel core_i3 7300
intel core_i5 4260u
lenovo thinkpad_l580 -
lenovo thinkpad_e480 -
intel core_i5 6500te
intel core_i7 6660u
lenovo thinkpad_p52s -
intel core_i7 6700
intel core_i5 6400t
intel core_i7 5850eq
intel core_i3 4330te
intel core_i7 5950hq
intel core_i7 6820hk
intel core_i7 4700ec
intel core_i3 4350
intel core_i7 4650u
intel core_i7 5650u
intel core_i5 6442eq
intel core_i7 4870hq
intel core_i5 4278u
intel core_i3 4340te
intel core_i5 7200u
intel core_i7 5600u
intel core_i5 4670t
intel core_i7 4710hq
intel core_i5 7267u
intel core_i3 6100t
intel core_i5 6260u
intel core_i3 6100te
intel core_i5 4200y
intel core_i5 4460s
intel core_i7 7700
intel core_i5 7442eq
intel core_i5 4670
intel core_i7 6820hq
intel core_i7 8706g
intel core_i7 4500u
intel core_i5 5287u
intel core_i5 6440eq
lenovo thinkpad_l380 -
intel core_i5 4570r
intel core_i3 4360
intel core_i7 5775r
intel core_i7 6700k
intel core_i3 8100h
intel core_i7 5750hq
intel core_i5 4302y
intel core_i5 8500t
lenovo thinkpad_x270 -
intel core_i5 6287u
intel core_i5 8500b
intel core_i5 6585r
intel core_i5 8600k
intel core_i5 4310u
intel core_i3 7100
lenovo thinkpad_p72 -
intel core_i7 8850h
intel core_i7 8700k
intel core_i3 7020u
intel core_i5 7287u
intel core_i7 7820hk
intel core_i7 4765t
intel core_i3 4100m
lenovo thinkpad_e580 -
intel core_i3 4030u
intel core_i5 4288u
intel core_i5 4690t
intel core_i3 6100u
intel core_i5 4590
intel core_i7 4785t
intel core_i7 6560u
intel core_i3 4100e
intel core_i5 4202y
lenovo thinkpad_x1_yoga -
intel core_i7 4980hq
lenovo thinkpad_t580 -
intel core_i7 4702mq
intel core_i7 8550u
intel core_i3 7100e
intel core_i7 6700te
intel core_i5 5575r
intel core_i3 6100e
intel core_i3 5020u
intel core_i3 4150t
intel core_i3 5010u
intel core_i3 4330
intel core_i3 7300t
intel core_i5 8400b
intel core_i5 4300y
intel core_i3 6157u
intel core_i5 4430
intel core_i7 4712hq
intel core_i7 7700hq
intel core_i5 4340m
intel core_i7 4770te
intel core_i7 8559u
intel core_i7 4790t
intel core_i7 4860hq
intel core_i3 4005u
intel core_i5 4360u
intel core_i5 4570
intel core_i7 4710mq
intel core_i5 4690s
intel core_i7 4950hq
lenovo thinkpad_p71 -
intel core_i5 4670s
intel core_i5 7y54
intel core_i7 8700
intel core_i5 5350h
intel core_i5 5675c
intel core_i7 8750h
intel core_i3 7167u
intel core_i5 4440
intel core_i7 7660u
intel core_i5 6685r
intel core_i5 4440s
intel core_i5 6267u
intel core_i5 4200h
intel core_i3 4130
intel core_i5 8400
intel core_i5 6600t
intel core_i7 7700k
intel core_i7 4900mq
intel core_i7 7567u
intel core_i3 6320
intel core_i5 6402p
intel core_i7 5557u
intel core_i7 4770t
lenovo thinkpad_x280 -
intel core_i3 4010y
intel core_i3 4110m
intel core_i5 4670r
intel core_i3 4158u
intel core_i5 4570t
intel core_i7 6870hq
lenovo thinkpad_yoga_370 -
intel core_i5 4308u
lenovo thinkpad_t480s -
intel core_i5 6300u
intel core_i3 4025u
intel core_i3 4340
intel core_i5 8600
intel core_i7 6600u
intel core_i5 6500t
intel core_i7 6970hq
intel core_i5 8400t
intel core_i3 6100
intel core_i7 7600u
intel core_i5 4220y
intel core_i3 6167u
intel core_i3 7100t
intel core_i5 7500
intel core_i7 4960hq
intel core_i7 5500u
intel core_i7 4770k
intel core_i3 6100h
intel core_i5 6360u
intel core_i3 4112e
intel core_i3 8145u
intel core_i7 4578u
intel core_i3 7102e
lenovo thinkpad_p52 -
intel core_i5 6600
intel core_i3 6098p
intel core_i5 7600k
intel core_i7 4770
intel core_i5 5350u
intel core_i3 7130u
intel core_i3 6006u
intel core_i5 4210u
intel core_i5 5300u
intel core_i9 8950hk
intel core_i5 7260u
intel core_i7 4771
intel core_i3 4000m
intel core_i7 5820k
intel core_i7 4770r
intel core_i3 8109u
intel core_i7 4700hq
intel core_i3 4350t
intel core_i7 4910mq
intel core_i3 7100h
intel core_i5 8265u
intel core_i3 4160
lenovo thinkpad_t480 -
intel core_i3 4370
intel core_i5 4250u
intel core_i5 4590t
lenovo thinkpad_11e -
intel core_i5 6200u
intel core_i7 4702ec
intel core_i5 4460t
intel core_i5 4422e
intel core_i7 5775c
intel core_i3 4170
intel core_i7 6820eq
intel core_i5 6440hq
intel core_i3 4370t
intel core_i7 8700t
intel core_i3 7100u
intel core_i7 4790
intel core_i7 8705g
intel core_i7 6785r
intel core_i5 4210h
intel core_i5 8600t
intel core_i5 7600t
intel core_i7 8565u
intel core_i5 6300hq
intel core_i3 4330t
intel core_i5 5675r
intel core_i3 8300t
intel core_i3 4010u
intel core_i7 7920hq
intel core_i5 7y57
intel core_i3 5157u
intel core_i5 4570te
intel core_i7 5700hq
intel core_i5 6400
intel core_i3 4120u
intel core_i5 4590s
intel core_i5 4200u
intel core_i7 4720hq
intel core_i5 5200u
intel core_i3 7101te
intel core_i3 6300t
intel core_i7 4770s
intel core_i7 4700eq
lenovo thinkpad_p51s -
intel core_i7 5700eq
intel core_i7 6822eq
intel core_i7 5850hq
intel core_i7 6770hq
intel core_i5 4410e
intel core_i3 8350k
intel core_i7 6700hq
intel core_i3 4110e
intel core_i7 4850hq
intel core_i5 7600
intel core_i3 8100t
intel core_i5 4460
intel core_i3 4150
intel core_i3 7350k
lenovo thinkpad_l380_yoga -
intel core_i7 8500y
intel core_i7 7y75
intel core_i5 5257u
intel core_i5 7360u
intel core_i5 4300u
intel core_i7 4712mq
intel core_i3 7320
intel core_i7 4550u
intel core_i7 7820eq
intel core_i7 7820hq
intel core_i3 4020y
intel core_i3 5005u
intel core_i3 7101e
lenovo thinkpad_x1_carbon -
intel core_i5 4430s
intel core_i3 4012y
intel core_i5 4350u
intel core_i3 4030y
intel core_i3 5015u
intel core_i5 4300m
intel core_i7 4800mq
intel core_i7 4810mq
intel core_i3 4102e
intel core_i3 4130t
intel core_i5 4670k
intel core_i5 6500
intel core_i7 7700t
intel core_i7 7560u
intel core_i5 8400h
lenovo thinkpad_l480 -
intel core_i7 8086k
intel core_i7 7500u
intel core_i7 6650u
intel core_i5 8305g
intel core_i5 7440hq
intel core_i7 4558u
intel core_i5 4258u
intel core_i5 6600k
intel core_i5 7300u
intel core_i3 8300
intel core_i5 7440eq
intel core_i5 8250u
intel core_i7 4700mq
lenovo thinkpad_t570 -
intel core_i7 6700t
intel core_i7 4600m
CVE-2018-16089 HIGH

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16090 MEDIUM

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16091 MEDIUM

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16092 MEDIUM

In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16093 MEDIUM

In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
lenovo xclarity_integrator *
CVE-2018-16094 MEDIUM

In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16095 MEDIUM

In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16096 MEDIUM

In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-16097 MEDIUM

LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
lenovo xclarity_integrator *
CVE-2018-9062 HIGH

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-74,

Products Affected

Vendor Product Version
lenovo thinkpad_l380_firmware *
lenovo e52-80_isk_firmware *
lenovo thinkpad_p51s_firmware *
lenovo e52-80_firmware *
lenovo thinkpad_x280_firmware *
lenovo thinkpad_s1_firmware *
lenovo v510-14ikb_firmware *
lenovo e42-80_isk_firmware *
lenovo thinkpad_t470_firmware *
lenovo thinkpad_p51_firmware *
lenovo thinkpad_l580_firmware *
lenovo thinkpad_p52_firmware *
lenovo thinkpad_x380_yoga_firmware *
lenovo miix_720-12ikb_firmware *
lenovo v310-14isk_firmware *
lenovo v510-15ikb_firmware *
lenovo v310-15isk_firmware *
lenovo thinkpad_p72_firmware *
lenovo thinkpad_t580_firmware *
lenovo thinkpad_p52s_firmware *
lenovo thinkpad_x1_carbon_firmware *
lenovo thinkpad_yoga_11e_firmware *
lenovo v310-15ikb_firmware *
lenovo thinkpad_x1_yoga_firmware *
lenovo thinkpad_x1_tablet_firmware *
lenovo thinkpad_t25_firmware *
lenovo thinkpad_e580_firmware *
lenovo thinkpad_e480_firmware *
lenovo thinkpad_t480_firmware *
lenovo thinkpad_yoga_370_firmware *
lenovo v310-14ikb_firmware *
lenovo thinkpad_p71_firmware *
lenovo thinkpad_x270_firmware *
lenovo thinkpad_t570_firmware *
lenovo thinkpad_t470p_firmware *
lenovo e42-80_firmware *
lenovo thinkpad_t480s_firmware *
lenovo thinkpad_t470s_firmware *
lenovo thinkpad_l480_firmware *
CVE-2018-9063 MEDIUM

MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional privilege is granted to the attacker beyond what is already possessed to run MapDrv.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
lenovo system_update *
CVE-2018-9064 MEDIUM

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2018-9065 LOW

In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.

CVSS 2.0

Severity: LOW

Problem Type: CWE-312,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2018-9066 HIGH

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo xclarity_administrator *
CVE-2018-9067 MEDIUM

The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo lenovo_help *
CVE-2018-9068 MEDIUM

The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-798,

Products Affected

Vendor Product Version
ibm system_x3250_m5_firmware *
ibm bladecenter_hs22_firmware *
lenovo nextscale_nx360_m5_firmware *
ibm flex_system_x880_m4_firmware *
lenovo flex_system_x440_m4_firmware *
ibm bladecenter_hs23_firmware *
ibm system_x3650_m4_bd_firmware *
ibm flex_system_x280_m4_firmware *
lenovo system_x3750_m4_firmware *
ibm system_x3300_m4_firmware *
ibm system_x3550_m4_firmware *
ibm flex_system_x440_m4_firmware *
lenovo flex_system_x480_x6_firmware *
lenovo system_x3650_m5_firmware *
ibm idataplex_dx360_m4_water_cooled_firmware *
ibm idataplex_dx360_m4_firmware *
lenovo system_x3250_m6_firmware *
ibm bladecenter_hs23e_firmware *
ibm system_x3100_m4_firmware *
ibm system_x3250_m4_firmware *
ibm nextscale_nx360_m4_firmware *
lenovo flex_system_x240_m5_firmware *
ibm flex_system_x220_m4_firmware *
lenovo system_x3950_x6_firmware *
lenovo flex_system_x240_m4_firmware *
lenovo flex_system_x880_firmware *
ibm system_x3750_m4_firmware *
ibm system_x3850_x6_firmware *
ibm system_x3650_m4_hd_firmware *
ibm system_x3650_m4_firmware *
ibm system_x3100_m5_firmware *
ibm system_x3530_m4_firmware *
lenovo system_x3550_m5_firmware *
lenovo flex_system_x280_x6_firmware *
ibm flex_system_x240_m4_firmware *
lenovo system_x3500_m5_firmware *
lenovo system_x3850_x6_firmware *
ibm flex_system_x480_m4_firmware *
ibm system_x3500_m4_firmware *
ibm flex_system_x222_m4_firmware *
ibm system_x3630_m4_firmware *
ibm system_x3950_x6_firmware *
CVE-2018-9069 HIGH

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H 0.7 5.2

CVSS 2.0

Severity: HIGH

Problem Type: CWE-362,

Products Affected

Vendor Product Version
hp 320s-14ikb *
hp 7000-15_u42_firmware *
hp yoga_720-13ikbr_firmware *
hp lenovo_ideapad_320s-14ikbr_firmware -
hp 520-15ikbrn_firmware *
hp 320-15ikbrn_touch_firmware *
hp 7000_u42_firmware *
hp lenovo_y720-15ikb_firmware *
hp r720-15ikbn_firmware *
hp yoga_720-13ikb_firmware *
lenovo v510-15ikb_firmware *
hp e43-80_kbl_firmware *
lenovo v310-15isk_firmware *
hp flex_5-1570_firmware *
hp lenovo_ideapad_320-15ikb(i+n)_firmware -
hp y720-15ikb_firmware *
hp v330-14ikb_firmware *
hp 710s_plus-13ikb_16g_firmware *
hp lenovo_ideapad_flex_5-1570_firmware *
hp lenovo_ideapad_520s-14ikbr_firmware -
hp lenovo_ideapad_320-15abr_firmware -
hp r720-15ikba_firmware *
hp y520-15ikbn_firmware *
hp 320s-15isk_firmware *
hp 710s_plus-3ikb_firmware *
hp b320-14ikb_firmware -
hp lenovo_yoga_520-15ikb_firmware *
hp y520-15ikba_firmware *
hp lenovo_ideapad_y520-15ikbn_firmware -
hp lenovo_tianyi_310-15ikb_firmware -
hp 510s-14isk_firmware *
hp lenovo_y520-15ikba_firmware *
hp lenovo_ideapad_720s-14ikb_firmware *
hp lenovo_ideapad_320-14ikb(i+n)_firmware -
lenovo e52-80_firmware *
hp 320-15ikbrn_firmware *
lenovo v510-14ikb_firmware *
hp lenovo_yoga_520-14ikb_firmware *
hp ideapad_2in1_14_firmware -
hp nano110-15ikb_firmware *
hp yoga_510-14isk_firmware *
lenovo v310-14isk_firmware *
hp 310s-14isk_firmware *
hp 520s-14ikb_firmware *
hp lenovo_ideapad_320s-15ikbr_firmware -
hp yoga_310-11iap_firmware *
hp 320s-15ikb_firmware *
hp rescuer_y520-15ikbm_firmware *
hp lenovo_ideapad_320-14ikb(i+a)_firmware -
lenovo v310-15ikb_firmware *
hp 720s-13ikb_firmware *
hp 320-17ikbrn *
hp yoga_720-15ikb_firmware *
hp flex_4-1470_firmware *
hp flex_5-1470_firmware *
hp v330-14isk_firmware *
lenovo v310-14ikb_firmware *
hp lenovo_ideapad_flex_5-1470_firmware *
hp lenovo_y520-15ikbm_firmware *
hp 710s_plus_touch-13ikb_firmware *
hp lenovo_tianyi_310-14ikb_firmware -
hp miix_720-12ikb *
hp xiaoxinair13ikbpro_firmware *
hp rescuer_r720-15ikbm_firmware *
lenovo e42-80_firmware *
hp nano110-14ikb_firmware -
hp 320-15ikbra_firmware *
hp lenovo_v720-14_firmware *
CVE-2018-9070 MEDIUM

For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo smart_assistant *
CVE-2018-9071 MEDIUM

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
lenovo chassis_management_module_firmware *
CVE-2018-9072 MEDIUM

In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
lenovo xclarity_integrator *
CVE-2018-9073 MEDIUM

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-798,

Products Affected

Vendor Product Version
lenovo chassis_management_module_firmware *
CVE-2018-9074 MEDIUM

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
lenovo lenovoemc_firmware *
CVE-2018-9075 HIGH

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo lenovoemc_firmware *
CVE-2018-9076 HIGH

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo lenovoemc_firmware *
CVE-2018-9077 HIGH

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo lenovoemc_firmware *
CVE-2018-9078 MEDIUM

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
lenovo storcenter_px2-300d_firmware 4.1.402.34662
lenovo px4-400r_firmware 4.1.402.34662
lenovo px12-450r_firmware 4.1.402.34662
lenovo storcenter_px6-300d_firmware 4.1.402.34662
lenovo storcenter_ix2-dl_firmware 4.1.402.34662
lenovo px4-300r_firmware 4.1.402.34662
lenovo px2-300d_firmware 4.1.402.34662
lenovo storcenter_px4-300r_firmware 4.1.402.34662
lenovo storcenter_px4-300d_firmware 4.1.402.34662
lenovo px4-300d_firmware 4.1.402.34662
lenovo px12-400r_firmware 4.1.402.34662
lenovo ix4-300d_firmware 4.1.402.34662
lenovo storcenter_ix4-300d_firmware 4.1.402.34662
lenovo storcenter_px12-450r_firmware 4.1.402.34662
lenovo storcenter_px12-400r_firmware 4.1.402.34662
lenovo storcenter_ix2_firmware 4.1.402.34662
lenovo px6-300d_firmware 4.1.402.34662
lenovo px4-400d_firmware 4.1.402.34662
lenovo ez_media_&_backup_center_firmware 4.1.402.34662
lenovo ix2_firmware 4.1.402.34662
CVE-2018-9079 HIGH

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-79,

Products Affected

Vendor Product Version
lenovo storcenter_px2-300d_firmware 4.1.402.34662
lenovo px4-400r_firmware 4.1.402.34662
lenovo px12-450r_firmware 4.1.402.34662
lenovo storcenter_px6-300d_firmware 4.1.402.34662
lenovo storcenter_ix2-dl_firmware 4.1.402.34662
lenovo px4-300r_firmware 4.1.402.34662
lenovo px2-300d_firmware 4.1.402.34662
lenovo storcenter_px4-300r_firmware 4.1.402.34662
lenovo storcenter_px4-300d_firmware 4.1.402.34662
lenovo px4-300d_firmware 4.1.402.34662
lenovo px12-400r_firmware 4.1.402.34662
lenovo ix4-300d_firmware 4.1.402.34662
lenovo storcenter_ix4-300d_firmware 4.1.402.34662
lenovo storcenter_px12-450r_firmware 4.1.402.34662
lenovo storcenter_px12-400r_firmware 4.1.402.34662
lenovo storcenter_ix2_firmware 4.1.402.34662
lenovo px6-300d_firmware 4.1.402.34662
lenovo px4-400d_firmware 4.1.402.34662
lenovo ez_media_&_backup_center_firmware 4.1.402.34662
lenovo ix2_firmware 4.1.402.34662
CVE-2018-9080 MEDIUM

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
lenovo storcenter_px2-300d_firmware 4.1.402.34662
lenovo px4-400r_firmware 4.1.402.34662
lenovo px12-450r_firmware 4.1.402.34662
lenovo storcenter_px6-300d_firmware 4.1.402.34662
lenovo storcenter_ix2-dl_firmware 4.1.402.34662
lenovo px4-300r_firmware 4.1.402.34662
lenovo px2-300d_firmware 4.1.402.34662
lenovo storcenter_px4-300r_firmware 4.1.402.34662
lenovo storcenter_px4-300d_firmware 4.1.402.34662
lenovo px4-300d_firmware 4.1.402.34662
lenovo px12-400r_firmware 4.1.402.34662
lenovo ix4-300d_firmware 4.1.402.34662
lenovo storcenter_ix4-300d_firmware 4.1.402.34662
lenovo storcenter_px12-450r_firmware 4.1.402.34662
lenovo storcenter_px12-400r_firmware 4.1.402.34662
lenovo storcenter_ix2_firmware 4.1.402.34662
lenovo px6-300d_firmware 4.1.402.34662
lenovo px4-400d_firmware 4.1.402.34662
lenovo ez_media_&_backup_center_firmware 4.1.402.34662
lenovo ix2_firmware 4.1.402.34662
CVE-2018-9081 LOW

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
lenovo storcenter_px2-300d_firmware 4.1.402.34662
lenovo px4-400r_firmware 4.1.402.34662
lenovo px12-450r_firmware 4.1.402.34662
lenovo storcenter_px6-300d_firmware 4.1.402.34662
lenovo storcenter_ix2-dl_firmware 4.1.402.34662
lenovo px4-300r_firmware 4.1.402.34662
lenovo px2-300d_firmware 4.1.402.34662
lenovo storcenter_px4-300r_firmware 4.1.402.34662
lenovo storcenter_px4-300d_firmware 4.1.402.34662
lenovo px4-300d_firmware 4.1.402.34662
lenovo px12-400r_firmware 4.1.402.34662
lenovo ix4-300d_firmware 4.1.402.34662
lenovo storcenter_ix4-300d_firmware 4.1.402.34662
lenovo storcenter_px12-450r_firmware 4.1.402.34662
lenovo storcenter_px12-400r_firmware 4.1.402.34662
lenovo storcenter_ix2_firmware 4.1.402.34662
lenovo px6-300d_firmware 4.1.402.34662
lenovo px4-400d_firmware 4.1.402.34662
lenovo ez_media_&_backup_center_firmware 4.1.402.34662
lenovo ix2_firmware 4.1.402.34662
CVE-2018-9082 MEDIUM

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
lenovo storcenter_px2-300d_firmware 4.1.402.34662
lenovo px4-400r_firmware 4.1.402.34662
lenovo px12-450r_firmware 4.1.402.34662
lenovo storcenter_px6-300d_firmware 4.1.402.34662
lenovo storcenter_ix2-dl_firmware 4.1.402.34662
lenovo px4-300r_firmware 4.1.402.34662
lenovo px2-300d_firmware 4.1.402.34662
lenovo storcenter_px4-300r_firmware 4.1.402.34662
lenovo storcenter_px4-300d_firmware 4.1.402.34662
lenovo px4-300d_firmware 4.1.402.34662
lenovo px12-400r_firmware 4.1.402.34662
lenovo ix4-300d_firmware 4.1.402.34662
lenovo storcenter_ix4-300d_firmware 4.1.402.34662
lenovo storcenter_px12-450r_firmware 4.1.402.34662
lenovo storcenter_px12-400r_firmware 4.1.402.34662
lenovo storcenter_ix2_firmware 4.1.402.34662
lenovo px6-300d_firmware 4.1.402.34662
lenovo px4-400d_firmware 4.1.402.34662
lenovo ez_media_&_backup_center_firmware 4.1.402.34662
lenovo ix2_firmware 4.1.402.34662
CVE-2018-9083 HIGH

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-9084 MEDIUM

In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
lenovo system_management_module_firmware *
CVE-2018-9085 MEDIUM

A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-276,

Products Affected

Vendor Product Version
ibm system_x3250_m5_firmware *
ibm flex_system_x480_x6_firmware *
lenovo flex_system_x440_m4_firmware *
ibm bladecenter_hs23_firmware *
ibm system_x3650_m4_bd_firmware *
lenovo system_x3750_m4_firmware *
ibm system_x3300_m4_firmware *
ibm system_x3550_m4_firmware *
ibm flex_system_x280_x6_firmware *
ibm flex_system_x440_m4_firmware *
ibm idataplex_dx360_m4_water_cooled_firmware *
ibm idataplex_dx360_m4_firmware *
ibm flex_system_x880_x6_firmware *
ibm bladecenter_hs23e_firmware *
ibm system_x3100_m4_firmware *
ibm system_x3250_m4_firmware *
ibm flex_system_x220_m4_firmware *
lenovo flex_system_x240_m4_firmware *
ibm system_x3750_m4_firmware *
ibm system_x3850_x6_firmware *
ibm system_x3650_m4_hd_firmware *
ibm system_x3650_m4_firmware *
ibm system_x3100_m5_firmware *
ibm system_x3530_m4_firmware *
ibm flex_system_x240_m4_firmware *
ibm system_x3500_m4_firmware *
ibm flex_system_x222_m4_firmware *
ibm system_x3630_m4_firmware *
ibm system_x3950_x6_firmware *
CVE-2018-9086 MEDIUM

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
lenovo thinkserver_rd640_firmware *
lenovo thinkserver_rd340_firmware *
lenovo thinkserver_rd440_firmware *
lenovo thinkserver_td340_firmware *