
CVE-2022-48188
https://notcve.org/view.php?id=CVE-2022-48188
05 Jun 2023 — A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-124495 • CWE-787: Out-of-bounds Write •

CVE-2022-40137
https://notcve.org/view.php?id=CVE-2022-40137
30 Jan 2023 — A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-40136
https://notcve.org/view.php?id=CVE-2022-40136
30 Jan 2023 — An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVE-2022-40135
https://notcve.org/view.php?id=CVE-2022-40135
30 Jan 2023 — An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVE-2022-40134
https://notcve.org/view.php?id=CVE-2022-40134
30 Jan 2023 — An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVE-2021-4210
https://notcve.org/view.php?id=CVE-2021-4210
22 Apr 2022 — A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. Una posible vulnerabilidad en la función de devolución de llamada SMI usada en el controlador NVME en algunos modelos Lenovo Desktop, ThinkStation y ThinkEdge puede permitir a un atacante con acceso local y altos privilegios ejecutar código arbitrario • https://support.lenovo.com/us/en/product_security/LEN-77639 • CWE-20: Improper Input Validation •

CVE-2021-3519
https://notcve.org/view.php?id=CVE-2021-3519
12 Nov 2021 — A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes. Se ha informado de una vulnerabilidad en algunos modelos de ordenadores de sobremesa de Lenovo que podía permitir el acceso no autorizado al menú de arranque, cuando la configuración de la BIOS "BIOS Password At Boot Device List" es Sí • https://support.lenovo.com/us/en/product_security/LEN-67440 • CWE-287: Improper Authentication •

CVE-2020-8321
https://notcve.org/view.php?id=CVE-2020-8321
09 Jun 2020 — A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. Una potencial vulnerabilidad en la función de devolución de llamada SMI usada en el controlador System Lock Preinstallation en algunos modelos Lenovo Notebook y ThinkStation, puede permitir una ejecución de código arbitraria • https://support.lenovo.com/us/en/product_security/LEN-30042 •

CVE-2019-6190
https://notcve.org/view.php?id=CVE-2019-6190
14 Feb 2020 — Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled. Lenovo fue notificado de una potencial vulnerabilidad de denegación de servicio, que afecta a varias versiones de la BIOS para Lenovo Desktop, Desktop - All in One y ThinkStation, lo que podría causar que los PCR sean borrados de fo... • https://exchange.xforce.ibmcloud.com/vulnerabilities/176178 • CWE-665: Improper Initialization •

CVE-2019-0130
https://notcve.org/view.php?id=CVE-2019-0130
13 Jun 2019 — Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access. Un XSS reflejado en la interfaz web para Accelerated Storage Manager de Intel® en RSTe de Intel® anterior a versión 5.5.0.2015, puede permitir que un usuario no autenticado pueda habilitar potencialmente la denegación de servicio por medio de un acceso a la red. • http://www.securityfocus.com/bid/108775 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •