
CVE-2023-43571
https://notcve.org/view.php?id=CVE-2023-43571
08 Nov 2023 — A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. Se informó de un desbordamiento del búfer en el módulo BiosExtensionLoader en algunos productos de Lenovo Desktop que puede permitir que un atacante local con privilegios elevados ejecute código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-43570
https://notcve.org/view.php?id=CVE-2023-43570
08 Nov 2023 — A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code. Se informó una vulnerabilidad potencial en la función de devolución de llamada SMI del controlador OemSmi que puede permitir que un atacante local con permisos elevados ejecute código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-20: Improper Input Validation •

CVE-2023-43569
https://notcve.org/view.php?id=CVE-2023-43569
08 Nov 2023 — A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. Se informó de un desbordamiento del búfer en el módulo OemSmi en algunos productos de escritorio Lenovo que puede permitir que un atacante local con privilegios elevados ejecute código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-43568
https://notcve.org/view.php?id=CVE-2023-43568
08 Nov 2023 — A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. Se informó una lectura excesiva del búfer en el módulo LemSecureBootForceKey en algunos productos de escritorio Lenovo que puede permitir que un atacante local con privilegios elevados revele información sensible. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-126: Buffer Over-read •

CVE-2023-43567
https://notcve.org/view.php?id=CVE-2023-43567
08 Nov 2023 — A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. Se informó de un desbordamiento del búfer en el módulo LemSecureBootForceKey en algunos productos de escritorio Lenovo que puede permitir que un atacante local con privilegios elevados ejecute código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-40136
https://notcve.org/view.php?id=CVE-2022-40136
30 Jan 2023 — An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVE-2022-40135
https://notcve.org/view.php?id=CVE-2022-40135
30 Jan 2023 — An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVE-2021-3519
https://notcve.org/view.php?id=CVE-2021-3519
12 Nov 2021 — A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes. Se ha informado de una vulnerabilidad en algunos modelos de ordenadores de sobremesa de Lenovo que podía permitir el acceso no autorizado al menú de arranque, cuando la configuración de la BIOS "BIOS Password At Boot Device List" es Sí • https://support.lenovo.com/us/en/product_security/LEN-67440 • CWE-287: Improper Authentication •