Vulnerabilities > Lenovo
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-22 | CVE-2021-3970 | Improper Input Validation vulnerability in Lenovo products A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code. | 6.7 |
2022-04-22 | CVE-2021-3971 | Unspecified vulnerability in Lenovo products A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable. | 6.7 |
2022-04-22 | CVE-2021-3972 | Unspecified vulnerability in Lenovo products A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | 6.7 |
2022-04-22 | CVE-2021-4210 | Unspecified vulnerability in Lenovo products A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | 6.7 |
2022-04-22 | CVE-2021-4211 | Improper Input Validation vulnerability in Lenovo products A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | 6.7 |
2022-04-22 | CVE-2021-4212 | Improper Input Validation vulnerability in Lenovo products A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | 6.7 |
2022-04-22 | CVE-2022-0192 | Uncontrolled Search Path Element vulnerability in Lenovo Pcmanager A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation. | 7.8 |
2022-04-22 | CVE-2022-0354 | Unspecified vulnerability in Lenovo System Update A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window. | 7.8 |
2022-04-22 | CVE-2022-0636 | Classic Buffer Overflow vulnerability in Lenovo Thin Installer A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash. | 5.5 |
2022-04-22 | CVE-2022-1107 | Improper Privilege Management vulnerability in Lenovo products During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code. | 6.7 |