Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.21% | — | Lenovo ThinksystemAILenovo ThinkstationAI | 13/9/2024 | 17/6/2026 | A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Aplazada | Media (6.7) | 0.17% | — | Lenovo ThinksystemAI | 13/9/2024 | 17/6/2026 | An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Analizada | Alta (7.2) | 1.1% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Firmware+64 | 15/4/2024 | 17/6/2026 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function. | |
| Modificada | Baja (2.3) | 0.16% | — | Lenovo Thinksystem Sr670 V2 Firmware | 16/2/2024 | 17/6/2026 | ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS… | |
| Modificada | Alta (7.2) | 0.40% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+54 | 25/10/2023 | 17/6/2026 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |
| Modificada | Alta (8.8) | 0.52% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+119 | 25/10/2023 | 17/6/2026 | An authenticated XCC user can change permissions for any user through a crafted API command. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+54 | 25/10/2023 | 17/6/2026 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |
| Modificada | Media (6.3) | 0.29% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+4 | 26/6/2023 | 17/6/2026 | A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute. | |
| Modificada | Alta (7.5) | 0.62% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+4 | 26/6/2023 | 17/6/2026 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server. | |
| Modificada | Alta (8.8) | 0.51% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | |
| Modificada | Alta (8.8) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | |
| Modificada | Media (5.9) | 0.45% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. | |
| Modificada | Media (4.9) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured | |
| Modificada | Media (6.5) | 0.36% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions. | |
| Modificada | Alta (8.8) | 0.50% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+143 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+132 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.3) | 0.41% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. | |
| Modificada | Media (6.5) | 0.63% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile VX Enclosure FirmwareLenovo Thinksystem D2 Enclosure Firmware+1 | 22/4/2022 | 17/6/2026 | An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile VX Enclosure FirmwareLenovo Thinksystem D2 Enclosure Firmware+1 | 22/4/2022 | 17/6/2026 | An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. | |
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. |