Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2021-42848MEDIUMAn information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user EPSS 0.7%CVE-2019-6194MEDIUMAn XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that coulEPSS 0.7%CVE-2018-9084System Management Module VulnerabilitiesEPSS 0.7%CVE-2018-16093LXCI for VMwareEPSS 0.7%CVE-2023-4856HIGH A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a EPSS 0.7%CVE-2018-9085Missing System x Flash Memory Write Protection Lock BitEPSS 0.7%CVE-2019-6182MEDIUMA stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an adminiEPSS 0.7%CVE-2019-6180MEDIUMA stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could alEPSS 0.7%CVE-2018-16096System Management Module VulnerabilitiesEPSS 0.6%CVE-2019-6195MEDIUMAn authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid EPSS 0.6%CVE-2020-8340MEDIUMA cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), priorEPSS 0.6%CVE-2022-34884HIGHA buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsEPSS 0.6%CVE-2020-8350HIGHAn authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalEPSS 0.6%CVE-2023-5079HIGHLenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could resulEPSS 0.6%CVE-2023-2992HIGHAn unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered underEPSS 0.6%CVE-2021-42851MEDIUMA vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard useEPSS 0.6%CVE-2018-16091System Management Module VulnerabilitiesEPSS 0.6%CVE-2023-0683HIGHA valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.EPSS 0.6%CVE-2023-25495MEDIUMA valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenEPSS 0.6%CVE-2022-1513HIGHA potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a speciaEPSS 0.6%