Lenovo
Lenovo Vantage: vulnerabilidades y CVE
Lenovo Vantage tiene 15 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15994 | Alta (7.3) | 0.16% | — | 13 ago 2026 | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated… |
| CVE-2026-12036 | Media (6.9) | 0.16% | — | 13 ago 2026 | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with… |
| CVE-2026-5070 | Media (6.4) | 0.26% | — | 16 abr 2026 | The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32 due to insufficient output escaping in the gallery template. This… |
| CVE-2026-1717 | Media (6.8) | 0.14% | — | 11 mar 2026 | An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated… |
| CVE-2026-1716 | Media (6.9) | 0.15% | — | 11 mar 2026 | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated… |
| CVE-2026-1715 | Media (6.9) | 0.15% | — | 11 mar 2026 | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated… |
| CVE-2025-13154 | Media (6.8) | 0.14% | — | 14 ene 2026 | An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges. |
| CVE-2025-6232 | Alta (8.5) | 0.18% | — | 17 jul 2025 | An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations. |
| CVE-2025-6231 | Alta (8.5) | 0.18% | — | 17 jul 2025 | An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file. |
| CVE-2025-6230 | Media (4.8) | 0.15% | — | 17 jul 2025 | A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands. |
| CVE-2024-12673 | Alta (8.5) | 0.18% | — | 12 feb 2025 | An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only… |
| CVE-2023-6044 | Media (6.8) | 0.19% | — | 19 ene 2024 | A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitrary code with elevated privileges. |
| CVE-2023-6043 | Alta (7.8) | 0.17% | — | 19 ene 2024 | A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges. |
| CVE-2020-8327 | Alta (7.8) | 0.37% | — | 14 abr 2020 | A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to… |
| CVE-2020-8316 | Media (4.4) | 0.27% | — | 14 abr 2020 | A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges. |
Otros productos de Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Thinkcentre M75n Firmware · 27Ideacentre G5-14imb05 Firmware · 27V50t-13imb Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre 3-07imb05 Firmware · 26Ideacentre Creator 5-14iob6 Firmware · 26Ideacentre C5-14imb05 Firmware · 26