Vulnerabilidades em Lenovo

394 resultados
Análise Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2023-4608MEDIUMAn authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This afEPSS 0.4%CVE-2026-6282HIGHA potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remoteEPSS 0.4%CVE-2019-6184A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalaEPSS 0.4%CVE-2025-8061HIGHA potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some LenoEPSS 0.4%CVE-2020-8337An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCEPSS 0.4%CVE-2019-6165HIGHA DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo haEPSS 0.4%CVE-2020-8327HIGHA privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo VantEPSS 0.4%CVE-2023-29058MEDIUMA valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass messageEPSS 0.4%CVE-2026-16793HIGHRemote Command Injection via OS Profile Password in Lenovo XClarity OrchestratorEPSS 0.4%CVE-2020-8324MEDIUMA vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could EPSS 0.4%CVE-2019-6170MEDIUMA potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some EPSS 0.4%CVE-2020-8341In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additionaEPSS 0.3%CVE-2019-6171MEDIUMA vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or phEPSS 0.3%CVE-2020-8321MEDIUMA potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStatiEPSS 0.3%CVE-2024-45103MEDIUMA valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileEPSS 0.3%CVE-2022-1109MEDIUMAn incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.EPSS 0.3%CVE-2022-1890MEDIUMA buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitraEPSS 0.3%CVE-2022-1891MEDIUMA buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to executeEPSS 0.3%CVE-2022-1892MEDIUMA buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to executeEPSS 0.3%CVE-2020-8351HIGHA privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user toEPSS 0.3%