Loading HuntDB...

Vulnerabilities

CVE-2023-4856

HIGH

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

Published Apr 15, 2024

CVE-2023-4855

HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

Published Apr 15, 2024

CVE-2024-27912

HIGH

A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets.

Published Apr 05, 2024

CVE-2024-27911

HIGH

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

Published Apr 05, 2024

CVE-2024-27910

MEDIUM

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

Published Apr 05, 2024

CVE-2024-27909

MEDIUM

A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.

Published Apr 05, 2024

CVE-2024-27908

MEDIUM

A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

Published Apr 05, 2024

CVE-2024-23592

MEDIUM

An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.

Published Apr 05, 2024

CVE-2023-25494

MEDIUM

A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.

Published Apr 05, 2024

CVE-2023-25493

MEDIUM

A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.

Published Apr 05, 2024

CVE-2023-5912

MEDIUM

A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables.

Published Apr 05, 2024

CVE-2023-4605

MEDIUM

A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

Published Apr 05, 2024

CVE-2023-5081

LOW

An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.

Published Jan 19, 2024

CVE-2023-5080

MEDIUM

A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.

Published Jan 19, 2024

CVE-2023-43577

MEDIUM

A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43576

MEDIUM

A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43575

MEDIUM

A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43574

MEDIUM

A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

Published Nov 08, 2023

CVE-2023-43573

MEDIUM

A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43572

MEDIUM

A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

Published Nov 08, 2023

CVE-2023-45079

MEDIUM

A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Published Nov 08, 2023

CVE-2023-45078

MEDIUM

A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Published Nov 08, 2023

CVE-2023-45077

MEDIUM

A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Published Nov 08, 2023

CVE-2023-45076

MEDIUM

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Published Nov 08, 2023

CVE-2023-45075

MEDIUM

A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

Published Nov 08, 2023

CVE-2023-43581

MEDIUM

A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43580

MEDIUM

A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43579

MEDIUM

A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43578

MEDIUM

A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43571

MEDIUM

A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43570

MEDIUM

A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-43569

MEDIUM

A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. 

Published Nov 08, 2023

CVE-2023-43568

MEDIUM

A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

Published Nov 08, 2023

CVE-2023-43567

MEDIUM

A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-5079

HIGH

Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in information disclosure.

Published Nov 08, 2023

CVE-2023-5078

MEDIUM

A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

Published Nov 08, 2023

CVE-2023-5075

MEDIUM

A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.

Published Nov 08, 2023

CVE-2023-4891

MEDIUM

A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

Published Nov 08, 2023

CVE-2023-4706

HIGH

A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.

Published Nov 08, 2023

CVE-2023-4632

HIGH

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

Published Nov 08, 2023

CVE-2022-4575

MEDIUM

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

Published Oct 30, 2023

CVE-2022-48189

MEDIUM

An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Oct 30, 2023

CVE-2022-4574

MEDIUM

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  

Published Oct 30, 2023

CVE-2022-4573

MEDIUM

An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Oct 30, 2023

CVE-2022-3701

HIGH

A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.

Published Oct 27, 2023

CVE-2022-34886

HIGH

A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.

Published Oct 27, 2023

CVE-2023-3112

HIGH

A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.

Published Oct 24, 2023

CVE-2023-4608

MEDIUM

An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

Published Oct 24, 2023

CVE-2023-4607

HIGH

An authenticated XCC user can change permissions for any user through a crafted API command.

Published Oct 24, 2023

CVE-2023-4606

HIGH

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

Published Oct 24, 2023