cbcvebase.

Lenovo Ideacentre Creator 5-14Iob6 Firmware vulnerabilities

25 known vulnerabilities affecting lenovo/ideacentre_creator_5-14iob6_firmware.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM24

Vulnerabilities

Page 2 of 2
CVE-2022-40135P4MEDIUMCVSS 4.4≤ m3gkt33a2023-01-30
CVE-2022-40135 [MEDIUM] CWE-125 CVE-2022-40135: An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2022-40136P4MEDIUMCVSS 4.4≤ m3gkt33a2023-01-30
CVE-2022-40136 [MEDIUM] CWE-125 CVE-2022-40136: An information leak vulnerability in SMI Handler used to configure platform settings over WMI in som An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2023-43568P4MEDIUMCVSS 4.4fixed in m3gkt3da2023-11-08
CVE-2023-43568 [MEDIUM] CWE-126 CVE-2023-43568: A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
nvd
CVE-2023-43574P4MEDIUMCVSS 4.4fixed in m3gkt3da2023-11-08
CVE-2023-43574 [MEDIUM] CWE-126 CVE-2023-43574: A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
nvd
CVE-2023-43572P4MEDIUMCVSS 4.4fixed in m3gkt3da2023-11-08
CVE-2023-43572 [MEDIUM] CWE-126 CVE-2023-43572: A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products th A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
nvd
Lenovo Ideacentre Creator 5-14Iob6 Firmware vulnerabilities | cvebase