Show filters
432 Total Results
Displaying 31-40 of 432
Sort by:
Attacker Value
Unknown

CVE-2024-45104

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
Attacker Value
Unknown

CVE-2024-45103

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
Attacker Value
Unknown

CVE-2024-45101

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.
0
Attacker Value
Unknown

CVE-2024-3100

Disclosure Date: September 13, 2024 (last updated September 14, 2024)
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-8105

Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown

CVE-2024-6004

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted.
Attacker Value
Unknown

CVE-2024-5210

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted.
Attacker Value
Unknown

CVE-2024-5209

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted.
Attacker Value
Unknown

CVE-2024-4782

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs.
Attacker Value
Unknown

CVE-2024-4781

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted.