Vulnerabilidades em Lenovo Group Ltd.

56 resultados
Análise Vexday

Com 56 CVEs catalogadas e nenhuma em exploração ativa no CISA KEV, a Lenovo apresenta taxa de exploração abaixo da média geral do catálogo, o que indica um perfil de risco relativamente contido no momento. Não há registros de vulnerabilidades críticas, provas de conceito públicas ou novas entradas nos últimos 90 dias, sugerindo estabilidade recente no volume de exposições conhecidas. A CVE mais relevante no contexto atual é CVE-2017-3761, com pontuação EPSS de 0,0421 — valor baixo em termos absolutos, mas suficiente para merecer atenção em ambientes que ainda não aplicaram a correção correspondente. Equipes de segurança devem verificar se essa vulnerabilidade mais antiga persiste em ativos legados, pois itens sem atualização tendem a representar o vetor de risco residual mais comum em fabricantes de hardware.

CVE-2016-8227—Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local EPSS 0.3%CVE-2017-3740—In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controllEPSS 0.3%CVE-2017-3754—Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with EPSS 0.3%CVE-2017-3763—An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accountsEPSS 0.3%CVE-2016-8221—Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded iEPSS 0.3%CVE-2016-8223—During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation softwEPSS 0.3%CVE-2016-8222—A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows EPSS 0.3%CVE-2016-8224—A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a syEPSS 0.3%CVE-2017-3747—Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is notEPSS 0.3%CVE-2018-9070—For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by presEPSS 0.3%CVE-2017-3775—Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate sigEPSS 0.3%CVE-2017-3765—In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HEPSS 0.3%CVE-2017-3741—In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functEPSS 0.3%CVE-2017-3748—On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2EPSS 0.2%CVE-2017-3749—On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge,EPSS 0.1%CVE-2017-3750—On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug BriEPSS 0.1%