Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2023-43581MEDIUMA buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2021-42849MEDIUMA weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device EPSS 0.2%CVE-2022-40137MEDIUMA buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arEPSS 0.2%CVE-2021-3720MEDIUMAn information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (LEPSS 0.2%CVE-2023-3078HIGHAn uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local aEPSS 0.2%CVE-2021-3718MEDIUMA denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics settiEPSS 0.2%CVE-2020-8342HIGHA race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.EPSS 0.2%CVE-2023-5078MEDIUMA vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOEPSS 0.2%CVE-2023-45077MEDIUMA memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to EPSS 0.2%CVE-2023-45078MEDIUMA memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges toEPSS 0.2%CVE-2023-45076MEDIUMA memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to EPSS 0.2%CVE-2023-45075MEDIUMA memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to writeEPSS 0.2%CVE-2023-45079MEDIUMA memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write toEPSS 0.2%CVE-2026-4145HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticatEPSS 0.2%CVE-2023-43568MEDIUMA buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with eleEPSS 0.2%CVE-2023-43572MEDIUMA buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevaEPSS 0.2%CVE-2023-43574MEDIUMA buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attackeEPSS 0.2%CVE-2026-0827MEDIUMDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in LenEPSS 0.2%CVE-2021-3463MEDIUMA null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause sysEPSS 0.2%CVE-2023-3112HIGHA vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to eEPSS 0.2%