Lenovo
Lenovo Filez: vulnerabilidades y CVE
Lenovo Filez tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2368 | Alta (7.5) | 0.13% | — | 11 mar 2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code. |
| CVE-2026-1068 | Media (6) | 0.08% | — | 11 mar 2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application. |
| CVE-2026-0520 | Baja (2.4) | 0.09% | — | 11 mar 2026 | A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file. |
| CVE-2025-6249 | Alta (8.4) | 0.16% | — | 17 jul 2025 | An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data. |
| CVE-2025-2070 | Media (5.1) | 0.14% | — | 25 abr 2025 | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user. |
| CVE-2025-2068 | Media (5.1) | 0.15% | — | 25 abr 2025 | An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user. |
| CVE-2024-8058 | Alta (7.6) | 0.30% | — | 16 dic 2024 | An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Ideacentre G5-14imb05 Firmware · 27Thinkcentre M75n Firmware · 27V50t-13imb Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Creator 5-14iob6 Firmware · 26Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre C5-14imb05 Firmware · 26Ideacentre 3-07imb05 Firmware · 26