Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.55% | — | Lenovo Thinkcentre M80t FirmwareLenovo Thinkcentre M80s FirmwareLenovo Thinkcentre M90t FirmwareLenovo Thinkcentre M90s Firmware+10 | 11/11/2020 | 17/6/2026 | Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT. | |
| Modificada | Baja (2.4) | 0.31% | — | Lenovo Thinkcentre E73 FirmwareLenovo Thinkcentre M73 FirmwareLenovo Qitian 4500 FirmwareLenovo Qitian B4550 Firmware+12 | 11/11/2020 | 17/6/2026 | In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes. | |
| Modificada | Alta (8.8) | 0.63% | — | Lenovo Thinkpad Stack Wireless Router Firmware | 14/10/2020 | 17/6/2026 | An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege. | |
| Modificada | Crítica (9.8) | 2.2% | — | Lenovo Cloud Networking Operating System | 14/10/2020 | 17/6/2026 | An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and… | |
| Modificada | Alta (7.8) | 0.42% | — | Lenovo Hardware Scan | 14/10/2020 | 17/6/2026 | A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege. | |
| Modificada | Alta (7.8) | 0.44% | — | Lenovo Diagnostics | 14/10/2020 | 17/6/2026 | A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system. | |
| Modificada | Media (6.4) | 0.23% | — | Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+14 | 14/10/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected. | |
| Modificada | Media (6.1) | 0.99% | — | Lenovo Enterprise Network Disk | 24/9/2020 | 17/6/2026 | A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing. | |
| Modificada | Media (6.1) | 1.1% | — | Lenovo Enterprise Network Disk | 24/9/2020 | 17/6/2026 | A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing. | |
| Modificada | Alta (7.8) | 0.33% | — | Lenovo 63 FirmwareLenovo H50-30g FirmwareLenovo M4500 FirmwareLenovo M4550 Firmware+23 | 24/9/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution | |
| Modificada | Media (5.5) | 0.25% | — | Lenovo System Interface Foundation | 15/9/2020 | 17/6/2026 | A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations. | |
| Modificada | Alta (7) | 0.22% | — | Lenovo System Update | 15/9/2020 | 17/6/2026 | A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege. | |
| Modificada | Media (6.1) | 0.64% | — | Lenovo Integrated Management Module 2 | 15/9/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in… | |
| Modificada | Baja (2.4) | 0.35% | — | Lenovo Thinkpad T490 (20nx) FirmwareLenovo Thinkpad T490 (20qx) FirmwareLenovo Thinkpad T490 (20rx) FirmwareLenovo Thinkpad T490s (20nx) Firmware+6 | 1/9/2020 | 17/6/2026 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx… | |
| Modificada | Media (6.8) | 0.31% | — | Lenovo Thinkpad A275 FirmwareLenovo Thinkpad A285 FirmwareLenovo Thinkpad A475 FirmwareLenovo Thinkpad A485 Firmware+4 | 1/9/2020 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access. | |
| Modificada | Alta (7.8) | 0.42% | — | Lenovo Drivers Management | 24/7/2020 | 17/6/2026 | An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.42% | — | Lenovo Drivers Management | 24/7/2020 | 17/6/2026 | A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.51% | — | Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+108 | 22/7/2020 | 17/6/2026 | Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers. | |
| Modificada | Media (6) | 0.55% | — | Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+129 | 22/7/2020 | 17/6/2026 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table. | |
| Modificada | Media (6.8) | 0.30% | — | Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E15 FirmwareLenovo Thinkpad R14 FirmwareLenovo Thinkpad S3 GEN 2 Firmware+34 | 9/6/2020 | 17/6/2026 | Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. | |
| Modificada | Media (6.8) | 0.33% | — | Lenovo Thinkpad T495s FirmwareLenovo Thinkpad X395 FirmwareLenovo Thinkpad T495 FirmwareLenovo Thinkpad A485 Firmware+3 | 9/6/2020 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+47 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. | |
| Modificada | Media (6.7) | 0.34% | — | Lenovo 130-14ast FirmwareLenovo 130-14ikb FirmwareLenovo 130-15ast FirmwareLenovo 130-15ikb Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. | |
| Modificada | Media (6.8) | 0.28% | — | Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+96 | 9/6/2020 | 17/6/2026 | An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. |