Show filters
432 Total Results
Displaying 51-60 of 432
Sort by:
Attacker Value
Unknown

CVE-2024-38509

Disclosure Date: July 26, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially crafted IPMI command.
0
Attacker Value
Unknown

CVE-2024-38508

Disclosure Date: July 26, 2024 (last updated July 28, 2024)
A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request.
0
Attacker Value
Unknown

CVE-2024-4696

Disclosure Date: June 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.
0
Attacker Value
Unknown

CVE-2024-3286

Disclosure Date: May 16, 2024 (last updated January 05, 2025)
A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.
0
Attacker Value
Unknown

CVE-2024-2659

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
0
Attacker Value
Unknown

CVE-2024-23594

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-23593

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager and escalate privileges.
0
Attacker Value
Unknown

CVE-2023-4857

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
0
Attacker Value
Unknown

CVE-2023-4856

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.
0
Attacker Value
Unknown

CVE-2023-4855

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.
0