Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2023-34420HIGHA valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web EPSS 1.3%CVE-2019-6188ThinkPad T460p and T470p BIOS Tamper MechanismEPSS 1.3%CVE-2021-3970MEDIUMA potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attaEPSS 1.3%CVE-2021-3849CRITICALAn authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System ManaEPSS 1.3%CVE-2021-3897CRITICALAn authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System MaEPSS 1.3%CVE-2021-3971MEDIUMA potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenlyEPSS 1.3%CVE-2026-14371HIGHThe Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to PowershelEPSS 1.2%CVE-2018-9083System Management Module VulnerabilitiesEPSS 1.2%CVE-2024-2659HIGH A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to exeEPSS 1.1%CVE-2023-4855HIGH A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to exeEPSS 1.1%CVE-2024-8279HIGHA privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perfEPSS 1.1%CVE-2024-8278HIGHA privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perfEPSS 1.1%CVE-2018-9071CMM Security VulnerabilityEPSS 1.1%CVE-2019-6177HIGHA vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to nEPSS 1.1%CVE-2024-38510HIGHA privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user wiEPSS 1.1%CVE-2020-8347MEDIUMA reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 tEPSS 1.1%CVE-2019-6176A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.EPSS 1.0%CVE-2019-6193HIGHAn information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthEPSS 1.0%CVE-2024-8280HIGHAn input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform commEPSS 1.0%CVE-2024-8281HIGHAn input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform commEPSS 1.0%