Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2020-8353MEDIUMPrior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) featureEPSS 0.6%CVE-2023-4606HIGHAn authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThEPSS 0.6%CVE-2024-38509HIGHA privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arEPSS 0.5%CVE-2023-34418HIGHA valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnEPSS 0.5%CVE-2024-27912HIGHA denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending EPSS 0.5%CVE-2024-27910MEDIUMA vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authenticatiEPSS 0.5%CVE-2021-3417MEDIUMAn internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), ifEPSS 0.5%CVE-2020-8356MEDIUMAn internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTEPSS 0.5%CVE-2024-27908MEDIUMA buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.EPSS 0.5%CVE-2023-4857HIGH An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI caEPSS 0.5%CVE-2020-8355MEDIUMAn internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provEPSS 0.5%CVE-2023-6540MEDIUMA vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payEPSS 0.5%CVE-2024-27909MEDIUMA denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.EPSS 0.5%CVE-2023-4607HIGHAn authenticated XCC user can change permissions for any user through a crafted API command.EPSS 0.5%CVE-2019-19757MEDIUMAn internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scriptiEPSS 0.5%CVE-2018-9073CMM Security VulnerabilityEPSS 0.5%CVE-2023-25492MEDIUMA valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a fEPSS 0.5%CVE-2023-29057HIGHA valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to EPSS 0.5%CVE-2023-3113HIGHAn unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could resulEPSS 0.5%CVE-2023-34421MEDIUMA valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API callEPSS 0.5%