Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2021-3519MEDIUMA vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password AtEPSS 0.2%CVE-2021-3614MEDIUMA vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under cEPSS 0.2%CVE-2024-23594MEDIUM A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operatiEPSS 0.2%CVE-2025-12048HIGHAn arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allowEPSS 0.2%CVE-2021-3453MEDIUMSome Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker wiEPSS 0.2%CVE-2021-3786MEDIUMA potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be usedEPSS 0.2%CVE-2023-43570MEDIUM A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permEPSS 0.2%CVE-2023-43577MEDIUMA buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privilegeEPSS 0.2%CVE-2023-43578MEDIUMA buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privilegEPSS 0.2%CVE-2023-43580MEDIUMA buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privEPSS 0.2%CVE-2023-43581MEDIUMA buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privilEPSS 0.2%CVE-2023-43579MEDIUMA buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileEPSS 0.2%CVE-2023-5075MEDIUMA buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevatedEPSS 0.2%CVE-2023-43567MEDIUMA buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevEPSS 0.2%CVE-2023-43576MEDIUMA buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegEPSS 0.2%CVE-2023-43573MEDIUMA buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attackerEPSS 0.2%CVE-2023-43571MEDIUMA buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevatEPSS 0.2%CVE-2023-43569MEDIUMA buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegesEPSS 0.2%CVE-2023-43575MEDIUMA buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevateEPSS 0.2%CVE-2020-8332MEDIUMA potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x serveEPSS 0.2%