Show filters
66 Total Results
Displaying 21-30 of 66
Sort by:
Attacker Value
Unknown

CVE-2022-1107

Disclosure Date: April 22, 2022 (last updated October 07, 2023)
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
Attacker Value
Unknown

CVE-2021-4212

Disclosure Date: April 22, 2022 (last updated October 07, 2023)
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-22952

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.
Attacker Value
Unknown

CVE-2022-22951

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
Attacker Value
Unknown

CVE-2021-3786

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
Attacker Value
Unknown

CVE-2021-3453

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
Attacker Value
Unknown

CVE-2021-21982

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.
Attacker Value
Unknown

CVE-2020-4008

Disclosure Date: December 16, 2020 (last updated November 28, 2024)
The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation.
Attacker Value
Unknown

CVE-2020-8341

Disclosure Date: September 01, 2020 (last updated November 28, 2024)
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Attacker Value
Unknown

CVE-2020-8335

Disclosure Date: September 01, 2020 (last updated November 28, 2024)
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.