Vulnerabilities > Lenovo
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-13 | CVE-2021-3463 | NULL Pointer Dereference vulnerability in Lenovo Power Management Driver A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error. | 4.4 |
2021-04-13 | CVE-2021-3462 | Unspecified vulnerability in Lenovo Power Management Driver A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object. | 7.8 |
2021-03-09 | CVE-2021-3417 | Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Orchestrator 1.0.0/1.1.0/1.2.0 An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. | 4.9 |
2021-03-09 | CVE-2020-8357 | Incorrect Default Permissions vulnerability in Lenovo Pcmanager 2.6.40.3154/2.8.90.11211/3.0.50.9162 A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations. | 5.5 |
2021-03-09 | CVE-2020-8356 | Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Orchestrator 1.0.0/1.1.0/1.2.0 An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. | 4.9 |
2021-02-10 | CVE-2020-8355 | Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Administrator An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating. | 4.9 |
2020-11-30 | CVE-2020-8351 | Improper Privilege Management vulnerability in Lenovo Pcmanager 2.6.40.3154/2.8.90.11211 A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges. | 7.8 |
2020-11-11 | CVE-2020-8354 | Unspecified vulnerability in Lenovo Notebook Firmware A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution. | 6.7 |
2020-11-11 | CVE-2020-8353 | Unspecified vulnerability in Lenovo products Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. | 6.7 |
2020-11-11 | CVE-2020-8352 | Unspecified vulnerability in Lenovo products In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes. low complexity lenovo | 2.4 |