Page 2 of 46 results (0.005 seconds)

CVSS: 4.4EPSS: 0%CPEs: 673EXPL: 0

An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 288EXPL: 0

Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. Realtek Audio Drivers para Windows, como se usan en Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS y 20BT anteriores a 6.0.8882.1 y 20KH y 20KG anteriores a 6.0.8907.1 (y en muchos otros productos Lenovo y no Lenovo), manejan mal la precarga de DLL. • https://support.lenovo.com/us/en/product_security/ps500315-realtek-audio-driver-vulnerability • CWE-428: Unquoted Search Path or Element •

CVSS: 8.0EPSS: 0%CPEs: 10EXPL: 0

A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. Se informó de una vulnerabilidad de inyección de comandos en algunos dispositivos Lenovo Personal Cloud Storage que podría permitir a un usuario autenticado ejecutar comandos del sistema operativo mediante el envío de un paquete diseñado al dispositivo • https://iknow.lenovo.com.cn/detail/dc_200017.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 6.3EPSS: 0%CPEs: 10EXPL: 0

A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. Se informó de una vulnerabilidad en algunos dispositivos Lenovo Personal Cloud Storage que podría permitir a un usuario no autenticado crear una cuenta de usuario estándar • https://iknow.lenovo.com.cn/detail/dc_200017.html • CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 10EXPL: 0

A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access. En algunos dispositivos Lenovo Personal Cloud Storage fue reportado una contraseña de administrador débil por defecto para la interfaz web y el puerto serie que podría permitir el acceso no autorizado al dispositivo a un atacante con acceso físico o a la red local • https://iknow.lenovo.com.cn/detail/dc_200017.html • CWE-798: Use of Hard-coded Credentials •