Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
Legacy Server BMC Remote Command Injection
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
0
Attacker Value
Unknown
CVE-2017-17833
Disclosure Date: April 23, 2018 (last updated November 26, 2024)
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
0
Attacker Value
Unknown
CVE-2017-3753
Disclosure Date: August 10, 2017 (last updated November 26, 2024)
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.
0