Vulnerabilities > Lenovo

DATE CVE VULNERABILITY TITLE RISK
2018-09-28 CVE-2018-9074 Path Traversal vulnerability in Lenovo Lenovoemc Firmware 4.1.402.34662
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal.
network
low complexity
lenovo CWE-22
6.5
2018-09-21 CVE-2018-12169 Improper Authentication vulnerability in multiple products
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.
low complexity
intel lenovo CWE-287
7.6
2018-07-30 CVE-2018-9066 Improper Input Validation vulnerability in Lenovo Xclarity Administrator
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.
network
low complexity
lenovo CWE-20
8.8
2018-07-30 CVE-2018-9065 Cleartext Storage of Sensitive Information vulnerability in Lenovo Xclarity Administrator
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.
network
high complexity
lenovo CWE-312
7.5
2018-07-30 CVE-2018-9064 Unspecified vulnerability in Lenovo Xclarity Administrator
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
network
low complexity
lenovo
8.8
2018-07-26 CVE-2018-9068 Use of Hard-coded Credentials vulnerability in multiple products
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected.
network
low complexity
lenovo ibm CWE-798
7.5
2018-07-19 CVE-2018-9062 Injection vulnerability in Lenovo products
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
low complexity
lenovo CWE-74
6.8
2018-07-13 CVE-2018-9070 Unspecified vulnerability in Lenovo Smart Assistant
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device.
high complexity
lenovo
6.4
2018-07-13 CVE-2018-9067 Unspecified vulnerability in Lenovo Help
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.
network
low complexity
lenovo
7.5
2018-05-04 CVE-2018-9063 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Lenovo System Update
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code.
local
low complexity
lenovo CWE-119
7.8