2023-05-01
|
CVE-2023-25492
|
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.
|
Thinkagile_hx1021_firmware, Thinkagile_hx1320_firmware, Thinkagile_hx1321_firmware, Thinkagile_hx1331_firmware, Thinkagile_hx1520\-R_firmware, Thinkagile_hx1521\-R_firmware, Thinkagile_hx2320\-E_firmware, Thinkagile_hx2321_firmware, Thinkagile_hx2330_firmware, Thinkagile_hx2331_firmware, Thinkagile_hx2720\-E_firmware, Thinkagile_hx3320_firmware, Thinkagile_hx3321_firmware, Thinkagile_hx3330_firmware, Thinkagile_hx3331_firmware, Thinkagile_hx3375_firmware, Thinkagile_hx3376_firmware, Thinkagile_hx3520\-G_firmware, Thinkagile_hx3521\-G_firmware, Thinkagile_hx3720_firmware, Thinkagile_hx3721_firmware, Thinkagile_hx5520\-C_firmware, Thinkagile_hx5520_firmware, Thinkagile_hx5521\-C_firmware, Thinkagile_hx5521_firmware, Thinkagile_hx5530_firmware, Thinkagile_hx5531_firmware, Thinkagile_hx7520_firmware, Thinkagile_hx7521_firmware, Thinkagile_hx7530_firmware, Thinkagile_hx7531_firmware, Thinkagile_hx7820_firmware, Thinkagile_hx7821_firmware, Thinkagile_hx_enclosure_firmware, Thinkagile_mx1020_firmware, Thinkagile_mx1021_on_se350_firmware, Thinkagile_mx3330\-F_firmware, Thinkagile_mx3330\-H_firmware, Thinkagile_mx3331\-F_firmware, Thinkagile_mx3331\-H_firmware, Thinkagile_mx3530\-H_firmware, Thinkagile_mx3530_f_firmware, Thinkagile_mx3531\-F_firmware, Thinkagile_mx3531_h_firmware, Thinkagile_vx1320_firmware, Thinkagile_vx2320_firmware, Thinkagile_vx2330_firmware, Thinkagile_vx3320_firmware, Thinkagile_vx3330_firmware, Thinkagile_vx3331_firmware, Thinkagile_vx3520\-G_firmware, Thinkagile_vx3530\-G_firmware, Thinkagile_vx3720_firmware, Thinkagile_vx5520_firmware, Thinkagile_vx5530_firmware, Thinkagile_vx7320_n_firmware, Thinkagile_vx7330_firmware, Thinkagile_vx7520_firmware, Thinkagile_vx7520_n_firmware, Thinkagile_vx7530_firmware, Thinkagile_vx7531_firmware, Thinkagile_vx7820_firmware, Thinkagile_vx_1se_firmware, Thinkagile_vx_2u4n_firmware, Thinkagile_vx_4u_firmware, Thinkedge_se450__firmware, Thinkstation_p920_firmware, Thinksystem_sd530_firmware, Thinksystem_sd630_v2_firmware, Thinksystem_sd650\-N_v2_firmware, Thinksystem_sd650_firmware, Thinksystem_sd650_v2_firmware, Thinksystem_se350_firmware, Thinksystem_sn550_firmware, Thinksystem_sn550_v2_firmware, Thinksystem_sn850_firmware, Thinksystem_sr150_firmware, Thinksystem_sr158_firmware, Thinksystem_sr250_firmware, Thinksystem_sr250_v2_firmware, Thinksystem_sr258_firmware, Thinksystem_sr258_v2_firmware, Thinksystem_sr530_firmware, Thinksystem_sr550_firmware, Thinksystem_sr570_firmware, Thinksystem_sr590_firmware, Thinksystem_sr630_firmware, Thinksystem_sr630_v2_firmware, Thinksystem_sr645_firmware, Thinksystem_sr645_v3_firmware, Thinksystem_sr650_firmware, Thinksystem_sr650_v2_firmware, Thinksystem_sr665_firmware, Thinksystem_sr665_v3_firmware, Thinksystem_sr670_firmware, Thinksystem_sr670_v2_firmware, Thinksystem_sr850_firmware, Thinksystem_sr850_v2_firmware, Thinksystem_sr850p_firmware, Thinksystem_sr860_firmware, Thinksystem_sr860_v2_firmware, Thinksystem_sr950_firmware, Thinksystem_st250_firmware, Thinksystem_st250_v2_firmware, Thinksystem_st258_firmware, Thinksystem_st258_v2_firmware, Thinksystem_st550_firmware, Thinksystem_st650_v2_firmware, Thinksystem_st658_v2_firmware
|
8.8
|
|
|
2019-03-14
|
CVE-2019-0135
|
Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated user to potentially enable escalation of privilege via local access. L-SA-00206
|
Rapid_storage_technology_enterprise, Thinkstation_p520_firmware, Thinkstation_p520c_firmware, Thinkstation_p720_firmware, Thinkstation_p920_firmware
|
7.8
|
|
|
2019-06-13
|
CVE-2019-0130
|
Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access.
|
Rapid_storage_technology_enterprise, Thinkstation_p520_firmware, Thinkstation_p520c_firmware, Thinkstation_p720_firmware, Thinkstation_p920_firmware
|
7.4
|
|
|
2020-02-14
|
CVE-2019-6190
|
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
|
510\-15ikl_firmware, 510s\-08ikl_firmware, A340\-22_iwl_firmware, A340\-22ast_firmware, A340\-22icb_firmware, A340\-24_iwl_firmware, A340\-24icb_firmware, Aio520\-22iku_firmware, Aio520\-24arr_firmware, Aio520\-24iku_firmware, Aio520\-27ikl_firmware, Aio_330\-20ast_firmware, Aio_330\-20igm_firmware, Aio_520\-24ast_firmware, H50\-30g_desktop_firmware, Ideacentre_310s\-08asr_firmware, Ideacentre_310s\-08igm_firmware, Ideacentre_510\-15icb_firmware, Ideacentre_510a\-15icb_firmware, Ideacentre_700_firmware, Ideacentre_720\-18apr_firmware, Ideacentre_720\-18icb_firmware, Ideacentre_730s\-24ikb_firmware, Legion_c530\-19icb_firmware, Legion_c730\-19ico_firmware, Legion_t530\-28apr_firmware, Legion_t530\-28apr_reflash_firmware, Legion_t530\-28icb_firmware, Legion_t530\-28icb_reflash_firmware, Legion_t730\-28ico_firmware, Legion_y520t_z370_firmware, Lenovo_63_desktop_firmware, Lenovo_v330\-15igm_firmware, M4500_desktop_firmware, M4500_id_desktop_firmware, M4550_id_desktop_firmware, Qitian_4500_desktop_firmware, Qitian_a815_firmware, Qitian_b4550_desktop_firmware, Qitian_b4650_firmware, Qitian_b5900_firmware, Qitian_m4550_desktop_firmware, Qitian_m4600_firmware, Qitian_m4650_firmware, Qt_a7400_firmware, Qt_b415_firmware, Qt_m410_firmware, Qt_m415_firmware, Thinkcenter_m700z_firmware, Thinkcenter_m800z_firmware, Thinkcentre_e73_desktop_firmware, Thinkcentre_e73s_desktop_firmware, Thinkcentre_e74_firmware, Thinkcentre_e74s_firmware, Thinkcentre_e74z_firmware, Thinkcentre_e75s_firmware, Thinkcentre_e75t_firmware, Thinkcentre_e93_firmware, Thinkcentre_e95z_firmware, Thinkcentre_e96z_firmware, Thinkcentre_m4500k_desktop_firmware, Thinkcentre_m4500q_firmware, Thinkcentre_m4500s_desktop_firmware, Thinkcentre_m4500t_desktop_firmware, Thinkcentre_m4600s_firmware, Thinkcentre_m4600t_firmware, Thinkcentre_m600_firmware, Thinkcentre_m610_firmware, Thinkcentre_m625q_firmware, Thinkcentre_m6500s_firmware, Thinkcentre_m6500t_firmware, Thinkcentre_m6600_firmware, Thinkcentre_m6600q_firmware, Thinkcentre_m6600s_firmware, Thinkcentre_m6600t_firmware, Thinkcentre_m700q_firmware, Thinkcentre_m700s_firmware, Thinkcentre_m700t_firmware, Thinkcentre_m700z_firmware, Thinkcentre_m710e_firmware, Thinkcentre_m710q_firmware, Thinkcentre_m710s_firmware, Thinkcentre_m710t_firmware, Thinkcentre_m715q_firmware, Thinkcentre_m715q_rr_firmware, Thinkcentre_m715s_firmware, Thinkcentre_m715t_firmware, Thinkcentre_m720q_firmware, Thinkcentre_m720s_firmware, Thinkcentre_m720t_firmware, Thinkcentre_m725s_firmware, Thinkcentre_m7300z_firmware, Thinkcentre_m73_desktop_firmware, Thinkcentre_m73_tiny_firmware, Thinkcentre_m73p_firmware, Thinkcentre_m79_firmware, Thinkcentre_m800_firmware, Thinkcentre_m800z_firmware, Thinkcentre_m810z_firmware, Thinkcentre_m818z_firmware, Thinkcentre_m820z_firmware, Thinkcentre_m8300z_firmware, Thinkcentre_m8350z_firmware, Thinkcentre_m83_firmware, Thinkcentre_m83z_firmware, Thinkcentre_m8500s_firmware, Thinkcentre_m8500t_firmware, Thinkcentre_m8600s_firmware, Thinkcentre_m8600t_firmware, Thinkcentre_m900_firmware, Thinkcentre_m900z_firmware, Thinkcentre_m90n\-1_firmware, Thinkcentre_m910q_firmware, Thinkcentre_m910s_firmware, Thinkcentre_m910t_firmware, Thinkcentre_m910x_firmware, Thinkcentre_m910z_firmware, Thinkcentre_m920q_firmware, Thinkcentre_m920s_firmware, Thinkcentre_m920t_firmware, Thinkcentre_m920x_firmware, Thinkcentre_m920z_firmware, Thinkcentre_m9350z_firmware, Thinkcentre_m93_firmware, Thinkcentre_m93p_firmware, Thinkcentre_m93z_firmware, Thinkcentre_m9500z_firmware, Thinkcentre_m9550z_firmware, Thinkcentre_s510_firmware, Thinkcentre_x1_aio_firmware, Thinkstation_c30_refresh_firmware, Thinkstation_d30_refresh_firmware, Thinkstation_e32_firmware, Thinkstation_p300_firmware, Thinkstation_p310_firmware, Thinkstation_p318_firmware, Thinkstation_p320_firmware, Thinkstation_p320_tiny_firmware, Thinkstation_p330_firmware, Thinkstation_p330_tiny_firmware, Thinkstation_p410_firmware, Thinkstation_p500_firmware, Thinkstation_p510_firmware, Thinkstation_p520_firmware, Thinkstation_p520c_firmware, Thinkstation_p700_firmware, Thinkstation_p710_firmware, Thinkstation_p720_firmware, Thinkstation_p900_firmware, Thinkstation_p910_firmware, Thinkstation_p920_firmware, Thinkstation_s30_refresh_firmware, V310z_firmware, V410z_firmware, V510z_firmware, V520s\-08ikl_firmware, V520t\-15ikl_firmware, V530\-22icb_firmware, V530\-24icb_firmware, V530s\-07icb_firmware, V540\-24iwl_firmware, Yangtian_afh110_firmware, Yangtian_afh81_desktop_firmware, Yangtian_afq150_firmware, Yangtian_mc_h110_firmware, Yangtian_mc_h110_pci_firmware, Yangtian_mc_h81_desktop_firmware, Yangtian_me_h110_firmware, Yangtian_mf_h110_pci_firmware, Yangtian_mf_h81_pci_desktop_firmware, Yangtian_ms_h81_desktop_firmware, Yangtian_tc_h110_pci_firmware, Yangtian_tc_h81_pci_desktop_firmware, Yangtian_wc_h110_pci_firmware, Yangtian_wcc_h81_pci_desktop_firmware, Yangtian_we_h110_firmware, Yangtian_wf_h110_pci_firmware, Yangtian_wf_h81_pci_desktop_firmware, Yangtian_ws_h81_desktop_firmware, Yangtian_ytm6900e\-00_firmware, Yogo_a940\-27icb_firmware, Yta8900f_firmware
|
N/A
|
|
|
2019-04-10
|
CVE-2019-6156
|
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
|
330\-14igm_firmware, 330\-15igm_firmware, 510\-15ikl_firmware, 510s\-08ikl_firmware, 530s\-07icb_firmware, Aio300\-23isu\(C5130\)_firmware, Aio520\-22ikl_firmware, Aio520\-22iku_firmware, Aio520\-24ikl_firmware, Aio520\-24iku_firmware, Aio520\-27ikl_firmware, Aio_910\-27ish_firmware, Aio_y910\-27ish_firmware, H50\-30g_desktop_firmware, Ideacentre_300\-20ish_firmware, Ideacentre_300s\-11ish_firmware, Ideacentre_510\-15icb_firmware, Ideacentre_510a\-15icb_firmware, Ideacentre_510s\-08ish_firmware, Ideacentre_520s\-23iku_firmware, Ideacentre_620s\-03ikl_firmware, Ideacentre_700_firmware, Ideacentre_720\-18icb_firmware, Ideacentre_730s\-24ikb_firmware, Legion_c530\-19icb_firmware, Legion_c730\-19ico_firmware, Legion_t530\-28icb_firmware, Legion_t730\-28ico_firmware, Legion_y520t_z370_firmware, Legion_y720_tower_firmware, Legion_y920_tower_firmware, Lenovo_63_firmware, M4500_firmware, M4500_id_firmware, M4550_id_firmware, Qitian_4500_firmware, Qitian_b4550_firmware, Qitian_b4650_firmware, Qitian_m4550_firmware, Qitian_m4600_firmware, Qitian_m4650_firmware, Qt_a7400_firmware, Qt_b415_firmware, Qt_m410_firmware, Qt_m415_firmware, Thinkcenter_m700z_firmware, Thinkcenter_m800z_firmware, Thinkcentre_e73_\(Sff\)_firmware, Thinkcentre_e73_\(Twr\)_firmware, Thinkcentre_e73s_firmware, Thinkcentre_e74_firmware, Thinkcentre_e74s_firmware, Thinkcentre_e74z_firmware, Thinkcentre_e75s_firmware, Thinkcentre_e75t_firmware, Thinkcentre_e93_\(Sff\)_firmware, Thinkcentre_e93_\(Twr\)_firmware, Thinkcentre_e95z_firmware, Thinkcentre_e96z_firmware, Thinkcentre_m4500k_firmware, Thinkcentre_m4500q_firmware, Thinkcentre_m4500s_firmware, Thinkcentre_m4500t_firmware, Thinkcentre_m4600s_firmware, Thinkcentre_m4600t_firmware, Thinkcentre_m610_firmware, Thinkcentre_m6500s_firmware, Thinkcentre_m6500t_firmware, Thinkcentre_m6600_firmware, Thinkcentre_m6600q_firmware, Thinkcentre_m6600s_firmware, Thinkcentre_m6600t_firmware, Thinkcentre_m700q_firmware, Thinkcentre_m700s_firmware, Thinkcentre_m700t_firmware, Thinkcentre_m700z_firmware, Thinkcentre_m710e_firmware, Thinkcentre_m710q_firmware, Thinkcentre_m710s_firmware, Thinkcentre_m710t_firmware, Thinkcentre_m720q_firmware, Thinkcentre_m720s_firmware, Thinkcentre_m720t_firmware, Thinkcentre_m7300z_firmware, Thinkcentre_m73_\(Sff\)_firmware, Thinkcentre_m73_\(Twr\)_firmware, Thinkcentre_m73_tiny_firmware, Thinkcentre_m73p_firmware, Thinkcentre_m800_firmware, Thinkcentre_m800z_firmware, Thinkcentre_m810z_firmware, Thinkcentre_m818z_firmware, Thinkcentre_m820z_firmware, Thinkcentre_m8300z_firmware, Thinkcentre_m8350z_firmware, Thinkcentre_m83_\(Sff\)_firmware, Thinkcentre_m83_\(Tiny\)_firmware, Thinkcentre_m83_\(Twr\)_firmware, Thinkcentre_m83z_\(Aio\)_firmware, Thinkcentre_m8500s_firmware, Thinkcentre_m8500t_firmware, Thinkcentre_m8600s_firmware, Thinkcentre_m8600t_firmware, Thinkcentre_m900_firmware, Thinkcentre_m900z_firmware, Thinkcentre_m910q_firmware, Thinkcentre_m910s_firmware, Thinkcentre_m910t_firmware, Thinkcentre_m910x_firmware, Thinkcentre_m910z_firmware, Thinkcentre_m920q_firmware, Thinkcentre_m920s_firmware, Thinkcentre_m920t_firmware, Thinkcentre_m920x_firmware, Thinkcentre_m920z_firmware, Thinkcentre_m93_firmware, Thinkcentre_m93p_\(Sff\)_firmware, Thinkcentre_m93p_\(Twr\)_firmware, Thinkcentre_m93p_tiny_firmware, Thinkcentre_m9500z_firmware, Thinkcentre_m9550z_firmware, Thinkcentre_s510_firmware, Thinkcentre_x1_aio_firmware, Thinkpad_e480_firmware, Thinkpad_e560p_firmware, Thinkpad_e570p_firmware, Thinkpad_e580_firmware, Thinkpad_l480_firmware, Thinkpad_l580_firmware, Thinkpad_s5_firmware, Thinkpad_t460_firmware, Thinkpad_t460p_firmware, Thinkpad_x260_firmware, Thinkpad_x380_yoga_firmware, Thinkstation_c30_refresh_firmware, Thinkstation_d30_refresh_firmware, Thinkstation_e32_firmware, Thinkstation_p300_firmware, Thinkstation_p310_firmware, Thinkstation_p318_firmware, Thinkstation_p320_firmware, Thinkstation_p320_tiny_firmware, Thinkstation_p330_firmware, Thinkstation_p330_tiny_firmware, Thinkstation_p410_firmware, Thinkstation_p500_firmware, Thinkstation_p510_firmware, Thinkstation_p520_firmware, Thinkstation_p520c_firmware, Thinkstation_p700_firmware, Thinkstation_p710_firmware, Thinkstation_p720_firmware, Thinkstation_p900_firmware, Thinkstation_p910_firmware, Thinkstation_p920_firmware, Thinkstation_s30_refresh_firmware, V310z\(Yt_s3150\)_firmware, V410z\(Yt_s4250\)_firmware, V510z_\(Yt_s5250\)_firmware, V520s\-08ikl_firmware, V520t\-15ikl_firmware, V530\-22icb\(Yt_s4350\)_firmware, V530\-24icb\(Yt_s5350\)_firmware, Yangtian_afh110_firmware, Yangtian_afh81_firmware, Yangtian_afq150_firmware, Yangtian_mc_h110_firmware, Yangtian_mc_h110_pci_firmware, Yangtian_mc_h81_firmware, Yangtian_me\/we_h110_firmware, Yangtian_mf\/wf_h110_pci_firmware, Yangtian_mf\/wf_h81_pci_firmware, Yangtian_ms\/ws_h81_firmware, Yangtian_tc\/wc_h110_pci_firmware, Yangtian_tc\/wcc_h81_pci_firmware, Yangtian_ytm6900e\-00_firmware, Yta8900f_firmware
|
3.3
|
|
|