11 results (0.004 seconds)

CVSS: 6.7EPSS: 0%CPEs: 174EXPL: 0

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-284: Improper Access Control •

CVSS: 4.4EPSS: 0%CPEs: 174EXPL: 0

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.7EPSS: 0%CPEs: 174EXPL: 0

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-798: Use of Hard-coded Credentials •

CVSS: 4.4EPSS: 0%CPEs: 174EXPL: 0

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.7EPSS: 0%CPEs: 174EXPL: 0

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •