Lenovo
Lenovo Thinkpad P53 Firmware: vulnerabilidades y CVE
Lenovo Thinkpad P53 Firmware tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-48189 | Media (6.7) | 0.19% | — | 30 oct 2023 | An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. |
| CVE-2023-2290 | Media (6.7) | 0.16% | — | 26 jun 2023 | A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code. |
| CVE-2022-40134 | Media (4.4) | 0.20% | — | 30 ene 2023 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. |
| CVE-2021-3786 | Media (5.5) | 0.23% | — | 12 nov 2021 | A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range. |
| CVE-2021-3599 | Media (6.7) | 0.29% | — | 12 nov 2021 | A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
| CVE-2019-18619 | Alta (7.8) | 0.51% | — | 22 jul 2020 | Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise… |
| CVE-2019-18618 | Media (6) | 0.55% | — | 22 jul 2020 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the… |
| CVE-2020-8323 | Media (6.7) | 0.33% | — | 9 jun 2020 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. |
| CVE-2020-8320 | Media (6.8) | 0.28% | — | 9 jun 2020 | An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. |
| CVE-2019-6188 | Crítica (9.8) | 1.3% | — | 12 nov 2019 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. |
| CVE-2019-6172 | Media (6.4) | 0.33% | — | 12 nov 2019 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. |
| CVE-2019-6170 | Media (6.4) | 0.35% | — | 12 nov 2019 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. |
Otros productos de Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Thinkcentre M75n Firmware · 27Ideacentre G5-14imb05 Firmware · 27V50t-13imb Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre 3-07imb05 Firmware · 26Ideacentre Creator 5-14iob6 Firmware · 26Ideacentre C5-14imb05 Firmware · 26