Show filters
432 Total Results
Displaying 221-230 of 432
Sort by:
Attacker Value
Unknown
CVE-2020-8356
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.
0
Attacker Value
Unknown
CVE-2020-8355
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating. The service log is only generated when requested by a privileged LXCA user and it is only accessible to the privileged LXCA user that requested the file and is then deleted.
0
Attacker Value
Unknown
CVE-2020-8351
Disclosure Date: November 30, 2020 (last updated February 22, 2025)
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2020-8352
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
0
Attacker Value
Unknown
CVE-2020-8354
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-8353
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
0
Attacker Value
Unknown
CVE-2020-8349
Disclosure Date: October 14, 2020 (last updated February 22, 2025)
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL.
0
Attacker Value
Unknown
CVE-2020-8338
Disclosure Date: October 14, 2020 (last updated February 22, 2025)
A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.
0
Attacker Value
Unknown
CVE-2020-8345
Disclosure Date: October 14, 2020 (last updated February 22, 2025)
A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege.
0
Attacker Value
Unknown
CVE-2020-8332
Disclosure Date: October 14, 2020 (last updated February 22, 2025)
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
0