Vulnerabilities > Lenovo > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-27 CVE-2022-34887 Improper Authentication vulnerability in Lenovo products
Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.
network
low complexity
lenovo CWE-287
5.4
2023-10-27 CVE-2022-3429 Unspecified vulnerability in Lenovo products
A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.
network
low complexity
lenovo
6.5
2023-10-25 CVE-2022-3698 Unspecified vulnerability in Lenovo Diagnostics and Hardwarescan Plugin
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
local
low complexity
lenovo
4.4
2023-10-25 CVE-2022-0353 Unspecified vulnerability in Lenovo products
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
local
low complexity
lenovo
4.4
2023-10-09 CVE-2022-3728 Insufficient Physical Protection Mechanism vulnerability in Lenovo products
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
low complexity
lenovo CWE-1263
6.8
2023-10-09 CVE-2022-48182 Insufficient Physical Protection Mechanism vulnerability in Lenovo products
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
low complexity
lenovo CWE-1263
6.8
2023-10-09 CVE-2022-48183 Insufficient Physical Protection Mechanism vulnerability in Lenovo products
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
low complexity
lenovo CWE-1263
6.8
2023-08-23 CVE-2022-3742 Classic Buffer Overflow vulnerability in Lenovo products
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
local
low complexity
lenovo CWE-120
6.7
2023-08-23 CVE-2022-3743 Information Exposure vulnerability in Lenovo products
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.
local
low complexity
lenovo CWE-200
4.4
2023-08-23 CVE-2022-3744 Use of Hard-coded Credentials vulnerability in Lenovo products
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
local
low complexity
lenovo CWE-798
6.7