Page 3 of 22 results (0.006 seconds)

CVSS: 7.2EPSS: 0%CPEs: 196EXPL: 0

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. • https://support.lenovo.com/us/en/product_security/LEN-87734 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 9.8EPSS: 0%CPEs: 10EXPL: 0

An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected. Se ha detectado una vulnerabilidad de omisión de autenticación en un servicio interno del firmware de Lenovo Fan Power Controller2 (FPC2) y Lenovo System Management Module (SMM) durante un que podría permitir a un atacante no autenticado ejecutar comandos en el SMM y el FPC2. SMM2 no está afectado • https://support.lenovo.com/us/en/product_security/LEN-72615 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •

CVSS: 9.8EPSS: 0%CPEs: 10EXPL: 0

An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected. Se ha detectado una vulnerabilidad de omisión de autenticación en la interfaz web del firmware de Lenovo Fan Power Controller2 (FPC2) y Lenovo System Management Module (SMM) que podría permitir a un atacante no autenticado ejecutar comandos en el SMM y el FPC2. SMM2 no está afectado • https://support.lenovo.com/us/en/product_security/LEN-72615 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •

CVSS: 6.5EPSS: 0%CPEs: 8EXPL: 0

In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented. En System Management Module (SMM), en versiones anteriores a la 1.06, si un atacante consigue iniciar sesión en el sistema operativo del dispositivo, la validación de las actualizaciones de software puede omitirse. • https://support.lenovo.com/us/en/solutions/LEN-24374 •

CVSS: 8.5EPSS: 0%CPEs: 8EXPL: 0

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user. En System Management Module (SMM), en versiones anteriores a la 1.06, un campo en la cabecera de las imágenes de actualización del firmware de SMM no está lo suficientemente saneado, lo que permite una inyección de comandos tras la autenticación en el SMM como el usuario root. • https://support.lenovo.com/us/en/solutions/LEN-24374 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •