Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user. | |
| Modificada | Alta (7.2) | 2.4% | — | Lenovo Thinkserver Rd340 FirmwareLenovo Thinkserver Rd440 FirmwareLenovo Thinkserver Rd640 FirmwareLenovo Thinkserver Td340 Firmware | 16/11/2018 | 17/6/2026 | In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users. | |
| Modificada | Media (4.9) | 0.66% | — | Lenovo Flex System X240 M4 FirmwareLenovo Flex System X440 M4 FirmwareLenovo System X3750 M4 FirmwareIBM Bladecenter Hs23 Firmware+25 | 16/11/2018 | 17/6/2026 | A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors. | |
| Modificada | Media (5.9) | 0.51% | — | Lenovo Chassis Management Module Firmware | 16/11/2018 | 17/6/2026 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets. | |
| Modificada | Media (5.3) | 0.98% | — | Lenovo Chassis Management Module Firmware | 16/11/2018 | 17/6/2026 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration. | |
| Modificada | Media (5.9) | 0.53% | — | HP 310s-14isk FirmwareHP 320-15ikbra FirmwareHP 320-15ikbrn FirmwareHP 320-15ikbrn Touch Firmware+64 | 2/10/2018 | 17/6/2026 | In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS. | |
| Modificada | Alta (8.8) | 0.72% | — | Lenovo Storcenter Px12-450r FirmwareLenovo Storcenter Px12-400r FirmwareLenovo Storcenter Px4-300r FirmwareLenovo Storcenter Px6-300d Firmware+16 | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain… | |
| Modificada | Media (4.7) | 0.55% | — | Lenovo Storcenter Px12-450r FirmwareLenovo Storcenter Px12-400r FirmwareLenovo Storcenter Px4-300r FirmwareLenovo Storcenter Px6-300d Firmware+16 | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site… | |
| Modificada | Media (5.9) | 0.73% | — | Lenovo Storcenter Px12-450r FirmwareLenovo Storcenter Px12-400r FirmwareLenovo Storcenter Px4-300r FirmwareLenovo Storcenter Px6-300d Firmware+16 | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session. | |
| Modificada | Crítica (9.8) | 1.2% | — | Lenovo Storcenter Px12-450r FirmwareLenovo Storcenter Px12-400r FirmwareLenovo Storcenter Px4-300r FirmwareLenovo Storcenter Px6-300d Firmware+16 | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device. | |
| Modificada | Alta (8.8) | 1.0% | — | Lenovo Storcenter Px12-450r FirmwareLenovo Storcenter Px12-400r FirmwareLenovo Storcenter Px4-300r FirmwareLenovo Storcenter Px6-300d Firmware+16 | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user… | |
| Modificada | Alta (8.1) | 1.6% | — | Lenovoemc Firmware | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a… | |
| Modificada | Alta (8.1) | 1.6% | — | Lenovoemc Firmware | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c… | |
| Modificada | Alta (8.1) | 4.1% | 💥 PoC | Lenovoemc Firmware | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires… | |
| Modificada | Media (6.5) | 0.97% | — | Lenovoemc Firmware | 28/9/2018 | 17/6/2026 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user. | |
| Modificada | Alta (7.6) | 0.55% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core I9+28 | 21/9/2018 | 17/6/2026 | Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware… | |
| Modificada | Alta (8.8) | 2.2% | — | Lenovo Xclarity Administrator | 30/7/2018 | 17/6/2026 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system. | |
| Modificada | Alta (7.5) | 0.46% | — | Lenovo Xclarity Administrator | 30/7/2018 | 17/6/2026 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those… | |
| Modificada | Alta (8.8) | 0.96% | — | Lenovo Xclarity Administrator | 30/7/2018 | 17/6/2026 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user. | |
| Modificada | Alta (7.5) | 1.1% | — | Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+38 | 26/7/2018 | 17/6/2026 | The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and… | |
| Modificada | Media (6.8) | 0.53% | — | Lenovo E42-80 FirmwareLenovo E42-80 ISK FirmwareLenovo E52-80 FirmwareLenovo E52-80 ISK Firmware+35 | 19/7/2018 | 17/6/2026 | In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. | |
| Modificada | Media (6.4) | 0.29% | — | Lenovo Smart Assistant | 13/7/2018 | 17/6/2026 | For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges,… | |
| Modificada | Alta (7.5) | 1.1% | — | Lenovo Help | 13/7/2018 | 17/6/2026 | The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI. | |
| Modificada | Alta (7.8) | 0.39% | — | Lenovo System Update | 4/5/2018 | 17/6/2026 | MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional… | |
| Modificada | Media (6.4) | 0.27% | — | Lenovo Flex System X240 M5 BiosLenovo Flex System X280 X6 BiosLenovo Flex System X480 X6 BiosLenovo Flex System X880 Bios+7 | 4/5/2018 | 17/6/2026 | Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code. |