Vulnerabilidades em Lenovo

381 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2022-3699HIGH A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior toEPSS 4.3%CVE-2021-3972MEDIUMA potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly nEPSS 3.0%CVE-2019-6168HIGHA vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.EPSS 2.5%CVE-2019-6167HIGHA vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.EPSS 2.5%CVE-2018-9086Legacy Server BMC Remote Command InjectionEPSS 2.4%CVE-2020-8349CRITICALAn internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOSEPSS 2.2%CVE-2019-6183A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that coulEPSS 1.9%CVE-2021-3922HIGHA race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.EPSS 1.9%CVE-2021-3969HIGHA Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,EPSS 1.9%CVE-2019-6192MEDIUMA potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow whicEPSS 1.7%CVE-2018-16089System Management Module VulnerabilitiesEPSS 1.7%CVE-2019-6175System Update VulnerabilityEPSS 1.7%CVE-2021-3617HIGHA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted networEPSS 1.7%CVE-2020-8329MEDIUMA denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggeredEPSS 1.5%CVE-2020-8330MEDIUMA denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggeredEPSS 1.5%CVE-2019-6158HIGHAn internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in EPSS 1.5%CVE-2019-6186A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated useEPSS 1.5%CVE-2019-6161An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC EPSS 1.4%CVE-2019-6179MEDIUMAn XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XEPSS 1.4%CVE-2019-6157MEDIUMIn various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes theEPSS 1.3%