Show filters
432 Total Results
Displaying 231-240 of 432
Sort by:
Attacker Value
Unknown

CVE-2020-8350

Disclosure Date: October 14, 2020 (last updated February 22, 2025)
An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege.
Attacker Value
Unknown

CVE-2020-8348

Disclosure Date: September 24, 2020 (last updated February 22, 2025)
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.
Attacker Value
Unknown

CVE-2020-8347

Disclosure Date: September 24, 2020 (last updated February 22, 2025)
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing.
Attacker Value
Unknown

CVE-2020-8333

Disclosure Date: September 24, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Attacker Value
Unknown

CVE-2020-8346

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
Attacker Value
Unknown

CVE-2020-8342

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.
Attacker Value
Unknown

CVE-2020-8340

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in the user's web browser if the user is convinced to visit a crafted URL, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the crafted URL. Impact is limited to the normal access restrictions and permissions of the user clicking the crafted URL, and subject to the user being able to connect to and already being authenticated to IMM2 or other systems. The JavaScript code is not executed on IMM2 itself.
Attacker Value
Unknown

CVE-2020-8341

Disclosure Date: September 01, 2020 (last updated November 28, 2024)
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
Attacker Value
Unknown

CVE-2020-8335

Disclosure Date: September 01, 2020 (last updated November 28, 2024)
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.
Attacker Value
Unknown

CVE-2020-8326

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.