Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.73% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented. | |
| Modificada | Alta (8.1) | 1.1% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability. | |
| Modificada | Media (6.1) | 0.65% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting. | |
| Modificada | Media (5.9) | 0.92% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails. | |
| Modificada | Alta (8.1) | 0.89% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow. | |
| Modificada | Alta (8.1) | 0.87% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file. | |
| Modificada | Alta (8.1) | 0.57% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows. | |
| Modificada | Alta (7.5) | 0.87% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection. | |
| Modificada | Alta (7.5) | 1.7% | — | Lenovo System Management Module Firmware | 27/11/2018 | 17/6/2026 | In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user. |