Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2024-33578HIGHA DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2022-4568HIGHA directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.EPSS 0.2%CVE-2025-6231HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%CVE-2025-6232HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%CVE-2022-4432MEDIUMA buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elEPSS 0.2%CVE-2022-4433MEDIUMA buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elEPSS 0.2%CVE-2022-4434MEDIUMA buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to EPSS 0.2%CVE-2022-4435MEDIUMA buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker EPSS 0.2%CVE-2023-25493MEDIUMA potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products EPSS 0.2%CVE-2024-33580HIGHA DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2026-13103HIGHA potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow aEPSS 0.2%CVE-2024-33579HIGHA DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2024-33581HIGHA DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with EPSS 0.2%CVE-2024-33582HIGHA DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privilegEPSS 0.2%CVE-2024-12673HIGHAn improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allowEPSS 0.2%CVE-2022-4575MEDIUM A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attackerEPSS 0.2%CVE-2023-25494MEDIUM A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attackeEPSS 0.2%CVE-2023-5912MEDIUM A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2022-3743MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2022-3745MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%