Vulnerabilities > Lenovo > Ideacentre AIO 3 24Ada6 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-01-30 CVE-2022-40137 Classic Buffer Overflow vulnerability in Lenovo products
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
local
low complexity
lenovo CWE-120
6.7
2022-04-22 CVE-2021-4210 Unspecified vulnerability in Lenovo products
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
local
low complexity
lenovo
6.7
2022-04-22 CVE-2021-4211 Improper Input Validation vulnerability in Lenovo products
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
local
low complexity
lenovo CWE-20
6.7