Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2023-34422MEDIUMA valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafteEPSS 0.5%CVE-2022-3429MEDIUMA denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an opeEPSS 0.5%CVE-2024-27911HIGHA vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.EPSS 0.5%CVE-2021-3473MEDIUMAn internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be EPSS 0.5%CVE-2019-6166MEDIUMA vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.EPSS 0.5%CVE-2023-4605MEDIUM A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve systemEPSS 0.5%CVE-2018-16097LXCI for VMware and LXCI for Microsoft System CenterEPSS 0.5%CVE-2024-3286HIGH A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restartEPSS 0.5%CVE-2026-6281HIGHA potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the locEPSS 0.4%CVE-2023-29056MEDIUMA valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC mustEPSS 0.4%CVE-2024-4696HIGHA privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commaEPSS 0.4%CVE-2020-8338HIGHA DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execEPSS 0.4%CVE-2020-8345HIGHA DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to versionEPSS 0.4%CVE-2020-8318HIGHA privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version thEPSS 0.4%CVE-2020-8326HIGHAn unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authentiEPSS 0.4%CVE-2020-8317HIGHA DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated uEPSS 0.4%CVE-2022-34888LOWThe Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normaEPSS 0.4%CVE-2020-8319HIGHA privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenEPSS 0.4%CVE-2022-3611HIGHAn information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized aEPSS 0.4%CVE-2023-0896HIGHA default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attackEPSS 0.4%