Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2026-1717MEDIUMAn input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allEPSS 0.1%CVE-2025-13453MEDIUMA potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the EPSS 0.1%CVE-2024-5474MEDIUMA potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2EPSS 0.1%CVE-2019-6197HIGHA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2026-63427HIGHAn authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrarEPSS 0.1%CVE-2019-6198HIGHA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2025-13154MEDIUMAn improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated locaEPSS 0.1%CVE-2025-13152HIGHA potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local auEPSS 0.1%CVE-2025-12046HIGHA DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated usEPSS 0.1%CVE-2024-4786LOWAn improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device EPSS 0.1%CVE-2026-6511MEDIUMDuring an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for WindowsEPSS 0.1%CVE-2026-6387HIGHA potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute EPSS 0.1%CVE-2025-13455HIGHA vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authEPSS 0.1%CVE-2026-0940HIGHA potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modEPSS 0.1%CVE-2026-8637HIGHA potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authentEPSS 0.1%CVE-2026-63426MEDIUMDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated loEPSS 0.1%CVE-2026-2368HIGHAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2025-2503MEDIUMAn improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file EPSS 0.1%CVE-2024-10254MEDIUMA potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attackerEPSS 0.1%CVE-2026-9046HIGHA potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusEPSS 0.1%