
CVE-2024-3100
https://notcve.org/view.php?id=CVE-2024-3100
13 Sep 2024 — A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-165524 • CWE-121: Stack-based Buffer Overflow •

CVE-2022-3746
https://notcve.org/view.php?id=CVE-2022-3746
23 Aug 2023 — A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-284: Improper Access Control •

CVE-2022-3745
https://notcve.org/view.php?id=CVE-2022-3745
23 Aug 2023 — A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-3744
https://notcve.org/view.php?id=CVE-2022-3744
23 Aug 2023 — A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-798: Use of Hard-coded Credentials •

CVE-2022-3743
https://notcve.org/view.php?id=CVE-2022-3743
23 Aug 2023 — A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-3742
https://notcve.org/view.php?id=CVE-2022-3742
23 Aug 2023 — A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. • https://support.lenovo.com/us/en/product_security/LEN-103710 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-4028
https://notcve.org/view.php?id=CVE-2023-4028
17 Aug 2023 — A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. Se ha identificado un desbordamiento de búfer en el controlador SystemUserMasterHddPwdDxe de algunos productos portátiles de Lenovo que puede permitir a un atacante con acceso local y privilegios elevados ejecutar código arbitrario. • https://support.lenovo.com/us/en/product_security/LEN-134879 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-1892
https://notcve.org/view.php?id=CVE-2022-1892
23 Jan 2023 — A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-91369 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-122: Heap-based Buffer Overflow •

CVE-2021-3614
https://notcve.org/view.php?id=CVE-2021-3614
16 Jul 2021 — A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage. Se ha reportado una vulnerabilidad en algunos sistemas de portátiles Lenovo que podría permitir a un atacante con acceso físico elevar los privilegios en determinadas condiciones durante una actualización de la BIOS llevada a cabo por Lenovo Vantage • https://support.lenovo.com/us/en/product_security/LEN-65529 • CWE-636: Not Failing Securely ('Failing Open') •

CVE-2021-3453
https://notcve.org/view.php?id=CVE-2021-3453
16 Jul 2021 — Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage. Algunos sistemas de portátiles, ThinkPad y ordenadores de sobremesa de Lenovo presentan módulos BIOS desprotegidos por Intel Boot Guard que podrían permitir a un atacante con acceso físico la habilidad de escribir en el almacenamiento flash SPI • https://support.lenovo.com/us/en/product_security/LEN-65529 • CWE-693: Protection Mechanism Failure •