CVE-2020-8337
https://notcve.org/view.php?id=CVE-2020-8337
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code. Se reportó una vulnerabilidad de ruta de búsqueda sin comillas en versiones anteriores a 1.0.83.0 de la aplicación Synaptics Smart Audio UWP asociada con los controladores de audio DCHU en las plataformas de Lenovo que podrían permitir a un usuario administrativo ejecutar código arbitrario • https://support.lenovo.com/us/en/product_security/len-30707 https://www.synaptics.com/sites/default/files/audio-driver-security-brief-2020-06-09.pdf • CWE-428: Unquoted Search Path or Element •
CVE-2020-8336
https://notcve.org/view.php?id=CVE-2020-8336
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. Lenovo implementó protecciones de Intel CSME Anti-rollback ARB en algunos modelos ThinkPad para impedir la reversión del Firmware CSME en flash • https://support.lenovo.com/us/en/product_security/LEN-30042 •
CVE-2020-8323
https://notcve.org/view.php?id=CVE-2020-8323
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. Una potencial vulnerabilidad en la función de devolución de llamada SMI usada en el controlador Legacy SD en algunos modelos Lenovo ThinkPad, ThinkStation y Lenovo Notebook, lo que puede permitir una ejecución de código arbitraria • https://support.lenovo.com/us/en/product_security/LEN-30042 •
CVE-2020-8320
https://notcve.org/view.php?id=CVE-2020-8320
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. Un shell interno fue incluido en la imagen del BIOS en algunos modelos de ThinkPad que podría permitir una escalada de privilegios • https://support.lenovo.com/us/en/product_security/LEN-30042 • CWE-269: Improper Privilege Management CWE-489: Active Debug Code •
CVE-2019-6192 – Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
https://notcve.org/view.php?id=CVE-2019-6192
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service. Ha sido reportada una posible vulnerabilidad en Lenovo Power Management Driver versiones anteriores a la versión 1.67.17.48, conllevando un desbordamiento de búfer que podría causar una denegación de servicio. Lenovo Power Management Driver suffers from buffer overflow vulnerability. • https://www.exploit-db.com/exploits/47771 http://packetstormsecurity.com/files/155656/Lenovo-Power-Management-Driver-Buffer-Overflow.html https://support.lenovo.com/solutions/LEN-29334 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •