Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2022-3611HIGHAn information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized aEPSS 0.4%CVE-2023-0896HIGHA default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attackEPSS 0.4%CVE-2026-75940CRITICALA vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attackEPSS 0.4%CVE-2023-4608MEDIUMAn authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This afEPSS 0.4%CVE-2019-6184—A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalaEPSS 0.4%CVE-2025-8061HIGHA potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some LenoEPSS 0.4%CVE-2020-8337—An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCEPSS 0.4%CVE-2019-6165HIGHA DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo haEPSS 0.4%CVE-2020-8327HIGHA privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo VantEPSS 0.4%CVE-2023-29058MEDIUMA valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass messageEPSS 0.4%CVE-2020-8324MEDIUMA vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could EPSS 0.4%CVE-2019-6170MEDIUMA potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some EPSS 0.4%CVE-2020-8341—In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additionaEPSS 0.3%CVE-2019-6171MEDIUMA vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or phEPSS 0.3%CVE-2020-8321MEDIUMA potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStatiEPSS 0.3%CVE-2024-45103MEDIUMA valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileEPSS 0.3%CVE-2022-1109MEDIUMAn incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.EPSS 0.3%CVE-2022-1890MEDIUMA buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitraEPSS 0.3%CVE-2022-1892MEDIUMA buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to executeEPSS 0.3%CVE-2022-1891MEDIUMA buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to executeEPSS 0.3%