Vulnerabilities > Lenovo > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-09 CVE-2021-3417 Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Orchestrator 1.0.0/1.1.0/1.2.0
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA.
network
low complexity
lenovo CWE-319
4.9
2021-03-09 CVE-2020-8357 Incorrect Default Permissions vulnerability in Lenovo Pcmanager 2.6.40.3154/2.8.90.11211/3.0.50.9162
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.
local
low complexity
lenovo CWE-276
5.5
2021-03-09 CVE-2020-8356 Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Orchestrator 1.0.0/1.1.0/1.2.0
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text.
network
low complexity
lenovo CWE-319
4.9
2021-02-10 CVE-2020-8355 Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Administrator
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating.
network
low complexity
lenovo CWE-319
4.9
2020-11-11 CVE-2020-8354 Unspecified vulnerability in Lenovo Notebook Firmware
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.
local
low complexity
lenovo
6.7
2020-11-11 CVE-2020-8353 Unspecified vulnerability in Lenovo products
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled.
local
low complexity
lenovo
6.7
2020-10-14 CVE-2020-8332 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Lenovo products
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution.
local
high complexity
lenovo CWE-367
6.4
2020-09-24 CVE-2020-8348 Cross-site Scripting vulnerability in Lenovo Enterprise Network Disk 6.1
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.
network
low complexity
lenovo CWE-79
6.1
2020-09-24 CVE-2020-8347 Cross-site Scripting vulnerability in Lenovo Enterprise Network Disk 6.1
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing.
network
low complexity
lenovo CWE-79
6.1
2020-09-15 CVE-2020-8346 Incorrect Default Permissions vulnerability in Lenovo System Interface Foundation 1.0.66.0/1.1.18.3/1.1.19.3
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
local
low complexity
lenovo CWE-276
5.5