Show filters
432 Total Results
Displaying 51-60 of 432
Sort by:
Attacker Value
Unknown
CVE-2024-38509
Disclosure Date: July 26, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially crafted IPMI command.
0
Attacker Value
Unknown
CVE-2024-38508
Disclosure Date: July 26, 2024 (last updated July 28, 2024)
A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request.
0
Attacker Value
Unknown
CVE-2024-4696
Disclosure Date: June 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.
0
Attacker Value
Unknown
CVE-2024-3286
Disclosure Date: May 16, 2024 (last updated January 05, 2025)
A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.
0
Attacker Value
Unknown
CVE-2024-2659
Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
0
Attacker Value
Unknown
CVE-2024-23594
Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A buffer overflow vulnerability was reported
in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014
that could allow a privileged attacker with local access to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-23593
Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A vulnerability was reported
in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014
that could allow a privileged attacker with local access to modify the boot manager and escalate privileges.
0
Attacker Value
Unknown
CVE-2023-4857
Disclosure Date: April 15, 2024 (last updated January 05, 2025)
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
0
Attacker Value
Unknown
CVE-2023-4856
Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.
0
Attacker Value
Unknown
CVE-2023-4855
Disclosure Date: April 15, 2024 (last updated January 05, 2025)
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.
0