Loading HuntDB...

Vulnerabilities

CVE-2022-3431

MEDIUM

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Published Oct 09, 2023

CVE-2022-3746

MEDIUM

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.

Published Aug 23, 2023

CVE-2022-3745

MEDIUM

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.

Published Aug 23, 2023

CVE-2022-3744

MEDIUM

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.

Published Aug 23, 2023

CVE-2022-3743

MEDIUM

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.

Published Aug 23, 2023

CVE-2022-3742

MEDIUM

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.

Published Aug 23, 2023

CVE-2023-34419

MEDIUM

A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Aug 17, 2023

CVE-2023-4030

HIGH

A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.

Published Aug 17, 2023

CVE-2023-4029

MEDIUM

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Aug 17, 2023

CVE-2023-4028

MEDIUM

A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Aug 17, 2023

CVE-2023-3078

HIGH

An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.

Published Aug 17, 2023

CVE-2023-34422

MEDIUM

A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.

Published Jun 26, 2023

CVE-2023-34421

MEDIUM

A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.

Published Jun 26, 2023

CVE-2023-34420

HIGH

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.

Published Jun 26, 2023

CVE-2023-34418

HIGH

A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.

Published Jun 26, 2023

CVE-2023-3113

HIGH

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.

Published Jun 26, 2023

CVE-2023-2993

MEDIUM

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

Published Jun 26, 2023

CVE-2023-2992

HIGH

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.

Published Jun 26, 2023

CVE-2023-2290

MEDIUM

A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Jun 26, 2023

CVE-2022-48188

MEDIUM

A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.

Published Jun 05, 2023

CVE-2022-48181

MEDIUM

An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.

Published Jun 05, 2023

CVE-2022-4569

HIGH

A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.

Published Jun 05, 2023

CVE-2022-48186

MEDIUM

A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure.

Published May 01, 2023

CVE-2022-4568

HIGH

A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

Published May 01, 2023

CVE-2023-0683

HIGH

A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.

Published May 01, 2023

CVE-2023-25492

MEDIUM

A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.

Published May 01, 2023

CVE-2023-0896

HIGH

A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.

Published May 01, 2023

CVE-2023-25495

MEDIUM

A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

Published Apr 28, 2023

CVE-2023-25496

HIGH

A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.

Published Apr 28, 2023

CVE-2023-29056

MEDIUM

A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

Published Apr 28, 2023

CVE-2023-29057

HIGH

A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.

Published Apr 28, 2023

CVE-2023-29058

MEDIUM

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

Published Apr 28, 2023

CVE-2022-34888

LOW

The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.

Published Jan 30, 2023

CVE-2022-34884

HIGH

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.

Published Jan 30, 2023

CVE-2022-40137

MEDIUM

A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Published Jan 30, 2023

CVE-2022-40136

MEDIUM

An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

Published Jan 30, 2023

CVE-2022-40135

MEDIUM

An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

Published Jan 30, 2023

CVE-2022-40134

MEDIUM

An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

Published Jan 30, 2023

CVE-2022-4816

MEDIUM

A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.

Published Jan 23, 2023

CVE-2022-3432

MEDIUM

A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Published Jan 23, 2023

CVE-2022-3430

MEDIUM

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

Published Jan 23, 2023

CVE-2022-1892

MEDIUM

A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Published Jan 23, 2023

CVE-2022-1891

MEDIUM

A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Published Jan 23, 2023

CVE-2022-1890

MEDIUM

A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.

Published Jan 23, 2023

CVE-2022-1109

MEDIUM

An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.

Published Jan 20, 2023

CVE-2022-4435

MEDIUM

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

Published Jan 05, 2023

CVE-2022-4434

MEDIUM

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.

Published Jan 05, 2023

CVE-2022-4433

MEDIUM

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

Published Jan 05, 2023

CVE-2022-4432

MEDIUM

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

Published Jan 05, 2023

CVE-2022-1513

HIGH

A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website.

Published Aug 23, 2022