Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2023-5081LOWAn information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettableEPSS 0.2%CVE-2024-4763HIGHAn insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) thEPSS 0.2%CVE-2026-63426MEDIUMDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated loEPSS 0.2%CVE-2022-4816MEDIUMA denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.EPSS 0.2%CVE-2024-23591LOWThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an atEPSS 0.2%CVE-2024-11679MEDIUMAn input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker EPSS 0.2%CVE-2023-6450MEDIUMAn incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resultEPSS 0.2%CVE-2026-10589MEDIUMA potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.EPSS 0.2%CVE-2026-6090HIGHA potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arEPSS 0.2%CVE-2025-14058LOWA potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical accEPSS 0.2%CVE-2026-12036MEDIUMAn improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could alEPSS 0.2%CVE-2023-2290MEDIUMA potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to eEPSS 0.2%CVE-2026-0421HIGHA potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in EPSS 0.2%CVE-2025-6249HIGHAn authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions EPSS 0.2%CVE-2026-15994HIGHDuring an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial VantEPSS 0.2%CVE-2025-8486HIGHA potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.EPSS 0.2%CVE-2025-6230MEDIUMA SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execuEPSS 0.2%CVE-2025-10581HIGHA potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a loEPSS 0.2%CVE-2025-12047MEDIUMA vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances,EPSS 0.2%CVE-2026-4135MEDIUMDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could alloEPSS 0.2%