CVE-2015-5684: Buffer Overflow
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5684?
CVE-2015-5684 has been classified as a medium severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2015-5684?
To fix CVE-2015-5684, update the affected Lenovo BIOS to the latest version provided by Lenovo.
Which Lenovo devices are affected by CVE-2015-5684?
CVE-2015-5684 affects various Lenovo notebook models, primarily those with specific firmware versions.
Is CVE-2015-5684 still a threat if I update my BIOS?
Once the BIOS is updated to a non-vulnerable version, CVE-2015-5684 should no longer pose a threat.
When was CVE-2015-5684 publicly disclosed?
CVE-2015-5684 was publicly disclosed on October 2015 after being fixed by Lenovo.