
CVE-2022-0353
https://notcve.org/view.php?id=CVE-2022-0353
24 Oct 2023 — A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. Se informó una vulnerabilidad de Denegación de Servicio (DoS) en las versiones Lenovo HardwareScanPlugin anteriores a 1.3.1.2 y Lenovo Diagnostics anteriores a 4.45 que podría permitir que un usuario local con acceso administrativo desencadene un bloqueo del sistema. • https://support.lenovo.com/us/en/product_security/LEN-102365 • CWE-400: Uncontrolled Resource Consumption •

CVE-2023-3112
https://notcve.org/view.php?id=CVE-2023-3112
24 Oct 2023 — A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges. Se informó una vulnerabilidad en el sensor de bloqueo virtual de Elliptic Labs para ThinkPad T14 Gen 3 que podría permitir a un atacante con acceso local ejecutar código con privilegios elevados. • https://support.lenovo.com/us/en/product_security/LEN-128081 • CWE-276: Incorrect Default Permissions •

CVE-2023-4608
https://notcve.org/view.php?id=CVE-2023-4608
24 Oct 2023 — An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. Un usuario de XCC autenticado con privilegios elevados puede realizar una inyección blind SQL en casos limitados a través de un comando API manipulado. Esto afecta a los servidores ThinkSystem v2 y v3 con XCC; Los servidores ThinkSystem v1 no se ven afectados. • https://support.lenovo.com/us/en/product_security/LEN-140960 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-4607
https://notcve.org/view.php?id=CVE-2023-4607
24 Oct 2023 — An authenticated XCC user can change permissions for any user through a crafted API command. Un usuario XCC autenticado puede cambiar los permisos de cualquier usuario mediante un comando API manipulado. • https://support.lenovo.com/us/en/product_security/LEN-140960 • CWE-269: Improper Privilege Management •

CVE-2023-4606
https://notcve.org/view.php?id=CVE-2023-4606
24 Oct 2023 — An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. Un usuario XCC autenticado con permiso de solo lectura puede cambiar la contraseña de un usuario diferente mediante un comando API manipulado. Esto afecta a los servidores ThinkSystem v2 y v3 con XCC; Los servidores ThinkSystem v1 no se ven afectados. • https://support.lenovo.com/us/en/product_security/LEN-140960 • CWE-862: Missing Authorization •

CVE-2022-48183
https://notcve.org/view.php?id=CVE-2022-48183
09 Oct 2023 — A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. Se informó una vulnerabilidad en ThinkPad T14s Gen 3 y X13 Gen3 que podría causar que el mecanismo de detección de manipulación del BIOS no se active en circunstancias específicas que podrían permitir el acceso no autorizado. • https://support.lenovo.com/us/en/product_security/LEN-106014 • CWE-1263: Improper Physical Access Control •

CVE-2022-48182
https://notcve.org/view.php?id=CVE-2022-48182
09 Oct 2023 — A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. Se informó una vulnerabilidad en ThinkPad T14s Gen 3 y X13 Gen3 que podría causar que el mecanismo de detección de manipulación del BIOS no se active en circunstancias específicas que podrían permitir el acceso no autorizado. • https://support.lenovo.com/us/en/product_security/LEN-106014 • CWE-1263: Improper Physical Access Control •

CVE-2022-3728
https://notcve.org/view.php?id=CVE-2022-3728
09 Oct 2023 — A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. Se informó una vulnerabilidad en ThinkPad T14s Gen 3 y X13 Gen3 que podría causar que el mecanismo de detección de manipulación del BIOS no se active en circunstancias específicas que podrían permitir el acceso no autorizado. • https://support.lenovo.com/us/en/product_security/LEN-106014 • CWE-1263: Improper Physical Access Control •

CVE-2022-3431
https://notcve.org/view.php?id=CVE-2022-3431
09 Oct 2023 — A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. Una vulnerabilidad potencial en un driver utilizado durante el proceso de fabricación de algunos dispositivos de consumo Lenovo Notebook que no se desactivó por error, puede permitir que un atacante con privilegios elevados modifique la configuración de ... • https://support.lenovo.com/us/en/product_security/LEN-94952 • CWE-276: Incorrect Default Permissions •

CVE-2022-3746
https://notcve.org/view.php?id=CVE-2022-3746
23 Aug 2023 — A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-284: Improper Access Control •