Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2021-3464HIGHA DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.EPSS 0.3%CVE-2021-4212MEDIUMA potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacEPSS 0.3%CVE-2022-48186MEDIUMA certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure.EPSS 0.3%CVE-2025-10699MEDIUMA vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.EPSS 0.3%CVE-2022-3728MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2022-3430MEDIUMA potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges toEPSS 0.3%CVE-2022-1108MEDIUMA potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could beEPSS 0.3%CVE-2020-8354MEDIUMA potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrEPSS 0.3%CVE-2022-0354HIGHA vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute codEPSS 0.3%CVE-2022-48183MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2022-48182MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2025-8557HIGHAn internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a EPSS 0.3%CVE-2021-3633HIGHA DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalationEPSS 0.3%CVE-2021-3719MEDIUMA potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some EPSS 0.3%CVE-2024-23592MEDIUMAn authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with pEPSS 0.3%CVE-2020-8346MEDIUMA denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.EPSS 0.2%CVE-2022-0192HIGHA DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.EPSS 0.2%CVE-2021-3550HIGHA DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.EPSS 0.2%CVE-2024-9046HIGHA DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2019-6156—In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additionaEPSS 0.2%