Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2026-16792HIGHGlobal TLS Certificate Validation Bypass in Lenovo XClarity OrchestratorEPSS 0.1%CVE-2026-14256MEDIUMELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a lEPSS 0.1%CVE-2025-11193MEDIUMA potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sEPSS 0.1%CVE-2022-3700MEDIUMA Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier thatEPSS 0.1%CVE-2025-8421MEDIUMAn improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could aEPSS 0.1%CVE-2025-13454MEDIUMA potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to senEPSS 0.1%CVE-2026-11813HIGHA potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated usEPSS 0.1%CVE-2026-18994HIGHA potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in theEPSS 0.1%CVE-2026-1652MEDIUMA potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local autheEPSS 0.1%CVE-2026-1653MEDIUMA potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenEPSS 0.1%CVE-2026-0520LOWA potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticEPSS 0.1%CVE-2025-6026LOWAn improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable ofEPSS 0.1%CVE-2026-1068MEDIUMAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2025-10237HIGHDuring an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could alEPSS 0.1%