Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2024-11679MEDIUMAn input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker EPSS 0.2%CVE-2026-10589MEDIUMA potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.EPSS 0.2%CVE-2023-6450MEDIUMAn incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resultEPSS 0.2%CVE-2023-2290MEDIUMA potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to eEPSS 0.2%CVE-2025-14058LOWA potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical accEPSS 0.2%CVE-2026-0421HIGHA potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in EPSS 0.2%CVE-2025-6249HIGHAn authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions EPSS 0.2%CVE-2025-10581HIGHA potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a loEPSS 0.2%CVE-2025-8486HIGHA potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.EPSS 0.2%CVE-2025-12047MEDIUMA vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances,EPSS 0.2%CVE-2025-6230MEDIUMA SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execuEPSS 0.2%CVE-2026-10588MEDIUMA potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.EPSS 0.2%CVE-2023-5080MEDIUMA privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identiEPSS 0.2%CVE-2025-1479MEDIUMAn open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to exEPSS 0.2%CVE-2024-4762HIGHAn improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escEPSS 0.1%CVE-2017-3772MEDIUMA vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.EPSS 0.1%CVE-2026-1716MEDIUMAn input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow aEPSS 0.1%CVE-2026-1715MEDIUMAn input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow aEPSS 0.1%CVE-2026-10587MEDIUMA potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System ManagemeEPSS 0.1%CVE-2025-1729MEDIUMA DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker toEPSS 0.1%