
CVE-2024-7756
https://notcve.org/view.php?id=CVE-2024-7756
13 Sep 2024 — A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell. • https://support.lenovo.com/us/en/product_security/LEN-165524 • CWE-489: Active Debug Code •

CVE-2023-25494
https://notcve.org/view.php?id=CVE-2023-25494
05 Apr 2024 — A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables. Se informó una vulnerabilidad potencial en el BIOS de algunos productos de escritorio, Smart Edge y ThinkStation que podría permitir que un atacante local con privilegios elevados escriba en variables NVRAM. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-125: Out-of-bounds Read •

CVE-2023-25493
https://notcve.org/view.php?id=CVE-2023-25493
05 Apr 2024 — A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. Se informó una vulnerabilidad potencial en el controlador de la herramienta de actualización del BIOS para algunos productos Desktop, Smart Edge, Smart Office y ThinkStation que podría permitir a un usuario local con privilegios elevados ejecutar código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-287: Improper Authentication CWE-306: Missing Authentication for Critical Function •

CVE-2023-5912
https://notcve.org/view.php?id=CVE-2023-5912
05 Apr 2024 — A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables. Se informó una posible vulnerabilidad de pérdida de memoria en algunos productos portátiles Lenovo que puede permitir que un atacante local con privilegios elevados escriba en variables NVRAM. • https://support.lenovo.com/us/en/product_security/LEN-155477 • CWE-787: Out-of-bounds Write •

CVE-2021-3452
https://notcve.org/view.php?id=CVE-2021-3452
16 Jul 2021 — A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. Una potencial vulnerabilidad en la función shutdown SMI callback del sistema en algunos modelos ThinkPad, puede permitir a un atacante con acceso local y privilegios elevados ejecutar código arbitrario • https://support.lenovo.com/us/en/product_security/LEN-65529 • CWE-20: Improper Input Validation •

CVE-2017-3775
https://notcve.org/view.php?id=CVE-2017-3775
04 May 2018 — Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code. Algunas versiones BIOS/UEFI del servidor x de Lenovo, cuando Secure Boot está habilitado por un administrador del sistema, no autentican correctamente el código firmado antes de cargarlo. Como resultado, un atacante con acceso físico al sistema podría cargar... • https://support.lenovo.com/us/en/solutions/LEN-20241 • CWE-287: Improper Authentication •

CVE-2017-3756
https://notcve.org/view.php?id=CVE-2017-3756
18 Aug 2017 — A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. Se identificó una vulnerabilidad de escalado de privilegios en Lenovo Active Protection System para versiones de sistemas ThinkPad anteriores a la 1.82.0.17. Un atacante con privilegios locales podría ejecutar código con privilegios de administrador a travé... • http://www.securityfocus.com/bid/100305 •

CVE-2017-3754
https://notcve.org/view.php?id=CVE-2017-3754
17 Jul 2017 — Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code. Algunos sistemas notebook de la marca Lenovo no tienen protecciones de escritura configuradas apropiadamente en el BIOS del sistema. Esto podría permitir a un atacante con acceso físico o administrativo a un sistema para ser capaz d... • https://support.lenovo.com/us/en/product_security/LEN-15084 •

CVE-2016-8226
https://notcve.org/view.php?id=CVE-2016-8226
26 Jan 2017 — The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure. La BIOS en sistemas Lenovo System X M5, M6 y X6, permite a administradores provocar una denegación de servicio a través de la actualización de una estructura de datos UEFI. • http://www.securityfocus.com/bid/95844 • CWE-19: Data Processing Errors •

CVE-2016-8222
https://notcve.org/view.php?id=CVE-2016-8222
30 Nov 2016 — A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability. Una vulnerabilidad ha sido identificada en un controlador de kernel firmado para la ... • http://www.securityfocus.com/bid/94409 • CWE-284: Improper Access Control •