Where
-Infinity
0

Vendor Risk Score

See how lenovo compares to other vendors in security performance

View Risk Score →

Software

lenovo thinkstation p920 workstation
35
lenovo ideacentre creator 5-14iob6
27
lenovo ideacentre creator 5-14iob6 firmware
27
lenovo ideacentre gaming 5-14iob6 firmware
27
lenovo thinkstation p520
27
lenovo thinkstation p520c
27
lenovo thinkstation p520c workstation firmware
27
lenovo thinkstation p330 tiny
25
lenovo thinkstation p330 tiny workstation firmware
25
lenovo ideacentre c5-14imb05
24
lenovo ideacentre c5-14mb05 firmware
24
lenovo ideacentre g5-14amr05 firmware
24
lenovo ideacentre g5-14imb05 firmware
24
lenovo ideacentre m75t gen 2
24
lenovo ideacentre m80s firmware
24
lenovo thinkcentre m75n
24
lenovo thinkstation p320 tiny workstation
24
lenovo thinkstation p720 workstation firmware
24
lenovo ideacentre 3
23
lenovo ideacentre 3-07ada05 firmware
23
lenovo ideacentre 3-07imb05 firmware
23
lenovo ideacentre m70t firmware
23
lenovo ideacentre m75q gen 2
23
lenovo ideacentre m75s gen 2 firmware
23
lenovo ideacentre m80q
23
lenovo ideacentre m90q tiny firmware
23
lenovo legion t7-34imz5
23
lenovo thinkcentre m920z all-in-one firmware
23
lenovo thinkcentre m625q
22
lenovo thinkcentre m625q firmware
22
lenovo thinkstation p330 workstation
22
lenovo thinkedge se30 firmware
21
lenovo v50t-13imb g2 firmware
21
lenovo thinkcentre m70a
20
lenovo thinkcentre m75t gen 2 firmware
20
lenovo thinkcentre m80s gen 3
20
lenovo thinkcentre m80t firmware
20
lenovo thinkcentre m80t gen 3
20
lenovo thinkcentre m90a gen 2 firmware
20
lenovo thinkcentre m90s firmware
20
lenovo thinkcentre m90s gen 3
20
lenovo thinkstation p340 tiny workstation
20
lenovo thinkstation p348
20
lenovo thinkstation p348 workstation firmware
20
lenovo thinkstation p350 workstation
20
lenovo ideacentre 5-14imb05 firmware
19
lenovo thinkcentre m630e
19
lenovo thinkcentre m70c firmware
19
lenovo thinkcentre m70q firmware
19
lenovo thinkcentre m70s firmware
19
Severity
7.3
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.

First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

First published (updated )
Severity
7
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.

First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

First published (updated )
Severity
7.3
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.

First published (updated )
Severity
8.7
OS Command Injection, Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.

First published (updated )
Severity
7
AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.

First published (updated )
Severity
1
AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.

First published (updated )
Severity
7.3
EPSS
0.13%
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

First published (updated )
Severity
6.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).

First published (updated )
Severity
8.4
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.

First published (updated )
Severity
7.3
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

First published (updated )
Severity
8.5
EPSS
0.10%
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

First published (updated )
Severity
5.1
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents.

First published (updated )
Severity
8.6
Path Traversal
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.

First published (updated )
Severity
8.7
OS Command Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

First published (updated )
Severity
5.2
AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

First published (updated )
Severity
7
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

First published (updated )
Severity
5.4
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

First published (updated )
Severity
6.9
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

First published (updated )
Severity
6.8
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

First published (updated )
Severity
6.8
Input Validation
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.

Remedy

Update Vantage LenovoProductivitySystemAddin to version 1.0.0.138 or later. LenovoProductivitySystemAddin is automatically updated by Lenovo Vantage and Baiying.
First published (updated )
Severity
6.9
Input Validation
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.

Remedy

Update Vantage DeviceSettingsSystemAddin to version 1.0.8.15 or later. DeviceSettingsSystemAddin is automatically updated by Lenovo Vantage and Baiying.
First published (updated )
Severity
6.9
Input Validation
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.

Remedy

Update Vantage DeviceSettingsSystemAddin to version 1.0.8.15 or later. DeviceSettingsSystemAddin is automatically updated by Lenovo Vantage and Baiying.
First published (updated )
Severity
6.8
Divide by Zero
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.

First published (updated )
Severity
6.9
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.

First published (updated )
Severity
7.5
AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.

First published (updated )
Severity
6
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203