Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2024-38511HIGHA privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user EPSS 1.0%CVE-2024-38508HIGHA privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an aEPSS 1.0%CVE-2024-38512HIGHA privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform coEPSS 1.0%CVE-2020-8348MEDIUMA DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 thEPSS 1.0%CVE-2018-16090System Management Module VulnerabilitiesEPSS 1.0%CVE-2018-16094System Management Module VulnerabilitiesEPSS 1.0%CVE-2018-16095System Management Module VulnerabilitiesEPSS 0.9%CVE-2021-3616CRITICALA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter EPSS 0.9%CVE-2019-6154MEDIUMA DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user withEPSS 0.9%CVE-2018-16092System Management Module VulnerabilitiesEPSS 0.9%CVE-2022-34886HIGHA remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing aEPSS 0.9%CVE-2026-19136HIGHA potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese markeEPSS 0.9%CVE-2019-19758MEDIUMA vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unautheEPSS 0.9%CVE-2019-6187A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriatEPSS 0.9%CVE-2019-6163MEDIUMA denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be wriEPSS 0.8%CVE-2019-6181MEDIUMA reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that couldEPSS 0.8%CVE-2018-16096System Management Module VulnerabilitiesEPSS 0.8%CVE-2021-42852HIGHA command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execuEPSS 0.8%CVE-2018-9072LXCI for VMwareEPSS 0.8%CVE-2021-3956MEDIUMA read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware EPSS 0.8%