Vulnerabilities in Lenovo

369 results
Vexday analysis

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2025-11193MEDIUMA potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sEPSS 0.1%CVE-2026-1652MEDIUMA potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local autheEPSS 0.1%CVE-2026-1653MEDIUMA potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenEPSS 0.1%CVE-2026-0520LOWA potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticEPSS 0.1%CVE-2025-13454MEDIUMA potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to senEPSS 0.1%CVE-2025-8421MEDIUMAn improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could aEPSS 0.1%CVE-2025-6026LOWAn improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable ofEPSS 0.1%CVE-2026-1068MEDIUMAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2025-10237HIGHDuring an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could alEPSS 0.1%