Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2019-6169MEDIUMA vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.EPSS 0.8%CVE-2021-42848MEDIUMAn information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user EPSS 0.7%CVE-2019-6194MEDIUMAn XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that coulEPSS 0.7%CVE-2018-9084—System Management Module VulnerabilitiesEPSS 0.7%CVE-2018-16093—LXCI for VMwareEPSS 0.7%CVE-2023-4856HIGH A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a EPSS 0.7%CVE-2018-9085—Missing System x Flash Memory Write Protection Lock BitEPSS 0.7%CVE-2019-6180MEDIUMA stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could alEPSS 0.7%CVE-2019-6182MEDIUMA stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an adminiEPSS 0.7%CVE-2018-16096—System Management Module VulnerabilitiesEPSS 0.6%CVE-2020-8340MEDIUMA cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), priorEPSS 0.6%CVE-2019-6195MEDIUMAn authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid EPSS 0.6%CVE-2022-34884HIGHA buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsEPSS 0.6%CVE-2020-8350HIGHAn authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalEPSS 0.6%CVE-2023-5079HIGHLenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could resulEPSS 0.6%CVE-2023-2992HIGHAn unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered underEPSS 0.6%CVE-2026-6282HIGHA potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remoteEPSS 0.6%CVE-2021-42851MEDIUMA vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard useEPSS 0.6%CVE-2018-16091—System Management Module VulnerabilitiesEPSS 0.6%CVE-2023-0683HIGHA valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.EPSS 0.6%