Vulnerabilities in Lenovo Group Ltd.

56 results
Vexday analysis

Com 56 CVEs catalogadas e nenhuma em exploração ativa no CISA KEV, a Lenovo apresenta taxa de exploração abaixo da média geral do catálogo, o que indica um perfil de risco relativamente contido no momento. Não há registros de vulnerabilidades críticas, provas de conceito públicas ou novas entradas nos últimos 90 dias, sugerindo estabilidade recente no volume de exposições conhecidas. A CVE mais relevante no contexto atual é CVE-2017-3761, com pontuação EPSS de 0,0421 — valor baixo em termos absolutos, mas suficiente para merecer atenção em ambientes que ainda não aplicaram a correção correspondente. Equipes de segurança devem verificar se essa vulnerabilidade mais antiga persiste em ativos legados, pois itens sem atualização tendem a representar o vetor de risco residual mais comum em fabricantes de hardware.

CVE-2017-3743—If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced SettiEPSS 0.7%CVE-2017-3742—In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two syEPSS 0.5%CVE-2018-9062—BIOS Modules Unprotected by Intel Boot Guard Vulnerable to Physical AttackEPSS 0.5%CVE-2017-3753—A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With thiEPSS 0.5%CVE-2016-8231—In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploiteEPSS 0.5%CVE-2018-9065—In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be aEPSS 0.5%CVE-2016-8229—A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHEPSS 0.5%CVE-2017-3752—An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on somEPSS 0.4%CVE-2017-3767—A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad pEPSS 0.4%CVE-2016-8235—Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute cEPSS 0.4%CVE-2017-3745—In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to EPSS 0.4%CVE-2018-16098—In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which EPSS 0.4%CVE-2017-3762—Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerpEPSS 0.4%CVE-2018-9063—MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerabiEPSS 0.4%CVE-2017-3756—A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17.EPSS 0.4%CVE-2017-3746—ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerabiliEPSS 0.4%CVE-2017-3757—An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand nEPSS 0.4%CVE-2016-8228—In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.EPSS 0.4%CVE-2017-3751—An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier tEPSS 0.4%CVE-2016-8225—Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execEPSS 0.4%