Vulnerabilities > Lenovo

DATE CVE VULNERABILITY TITLE RISK
2023-10-27 CVE-2022-3700 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Lenovo products
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.
local
high complexity
lenovo CWE-367
6.3
2023-10-27 CVE-2022-3701 Improper Privilege Management vulnerability in Lenovo products
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.
local
low complexity
lenovo CWE-269
7.8
2023-10-27 CVE-2022-3702 Unspecified vulnerability in Lenovo products
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.
local
low complexity
lenovo
7.1
2023-10-27 CVE-2022-34886 Out-of-bounds Write vulnerability in Lenovo products
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.
network
low complexity
lenovo CWE-787
8.8
2023-10-27 CVE-2022-34887 Improper Authentication vulnerability in Lenovo products
Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.
network
low complexity
lenovo CWE-287
5.4
2023-10-27 CVE-2022-3429 Unspecified vulnerability in Lenovo products
A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.
network
low complexity
lenovo
6.5
2023-10-25 CVE-2022-3698 Unspecified vulnerability in Lenovo Diagnostics and Hardwarescan Plugin
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
local
low complexity
lenovo
4.4
2023-10-25 CVE-2022-3699 Out-of-bounds Write vulnerability in Lenovo products
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
local
low complexity
lenovo CWE-787
7.8
2023-10-25 CVE-2023-4606 Missing Authorization vulnerability in Lenovo products
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
network
low complexity
lenovo CWE-862
8.1
2023-10-25 CVE-2023-4607 Improper Privilege Management vulnerability in Lenovo products
An authenticated XCC user can change permissions for any user through a crafted API command.
network
low complexity
lenovo CWE-269
8.8