
CVE-2022-34888
https://notcve.org/view.php?id=CVE-2022-34888
30 Jan 2023 — The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. • https://support.lenovo.com/us/en/product_security/LEN-87734 • CWE-184: Incomplete List of Disallowed Inputs CWE-697: Incorrect Comparison •

CVE-2022-34884
https://notcve.org/view.php?id=CVE-2022-34884
30 Jan 2023 — A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. • https://support.lenovo.com/us/en/product_security/LEN-87734 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2022-40137
https://notcve.org/view.php?id=CVE-2022-40137
30 Jan 2023 — A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-40136
https://notcve.org/view.php?id=CVE-2022-40136
30 Jan 2023 — An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. • https://support.lenovo.com/us/en/product_security/LEN-94953 • CWE-125: Out-of-bounds Read •

CVE-2021-3519
https://notcve.org/view.php?id=CVE-2021-3519
12 Nov 2021 — A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes. Se ha informado de una vulnerabilidad en algunos modelos de ordenadores de sobremesa de Lenovo que podía permitir el acceso no autorizado al menú de arranque, cuando la configuración de la BIOS "BIOS Password At Boot Device List" es Sí • https://support.lenovo.com/us/en/product_security/LEN-67440 • CWE-287: Improper Authentication •

CVE-2020-8321
https://notcve.org/view.php?id=CVE-2020-8321
09 Jun 2020 — A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. Una potencial vulnerabilidad en la función de devolución de llamada SMI usada en el controlador System Lock Preinstallation en algunos modelos Lenovo Notebook y ThinkStation, puede permitir una ejecución de código arbitraria • https://support.lenovo.com/us/en/product_security/LEN-30042 •

CVE-2019-6190
https://notcve.org/view.php?id=CVE-2019-6190
14 Feb 2020 — Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled. Lenovo fue notificado de una potencial vulnerabilidad de denegación de servicio, que afecta a varias versiones de la BIOS para Lenovo Desktop, Desktop - All in One y ThinkStation, lo que podría causar que los PCR sean borrados de fo... • https://exchange.xforce.ibmcloud.com/vulnerabilities/176178 • CWE-665: Improper Initialization •

CVE-2019-0130
https://notcve.org/view.php?id=CVE-2019-0130
13 Jun 2019 — Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access. Un XSS reflejado en la interfaz web para Accelerated Storage Manager de Intel® en RSTe de Intel® anterior a versión 5.5.0.2015, puede permitir que un usuario no autenticado pueda habilitar potencialmente la denegación de servicio por medio de un acceso a la red. • http://www.securityfocus.com/bid/108775 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-6156
https://notcve.org/view.php?id=CVE-2019-6156
10 Apr 2019 — In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected. En los sistemas Lenovo, SMM BIOS Write Protection se utiliza para evitar la escritura en... • https://support.lenovo.com/solutions/LEN-26332 • CWE-667: Improper Locking •

CVE-2019-0135
https://notcve.org/view.php?id=CVE-2019-0135
14 Mar 2019 — Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated user to potentially enable escalation of privilege via local access. L-SA-00206 Los permisos inapropiados en el instalador para Accelerated Storage Manager de Intel® en RSTe de Intel® anterior a versión 5.5.0.2015, pueden permitir que un usuario autenticado habilite potencialmente una escalada de privilegios por medio de un acceso local. L-SA-00206. • https://support.lenovo.com/us/en/product_security/LEN-27843 • CWE-264: Permissions, Privileges, and Access Controls •