Lenovo Thinkcentre E75S Firmware vulnerabilities

5 known vulnerabilities affecting lenovo/thinkcentre_e75s_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2022-40137MEDIUMCVSS 6.7vm16kt69a2023-01-30
CVE-2022-40137 [MEDIUM] CWE-120 CVE-2022-40137: A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local acce A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
nvd
CVE-2022-40134MEDIUMCVSS 4.4vm16kt68a2023-01-30
CVE-2022-40134 [MEDIUM] CWE-125 CVE-2022-40134: An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
nvd
CVE-2019-6190MEDIUMCVSS 5.5fixed in m16kt61a2020-02-14
CVE-2019-6190 [MEDIUM] CWE-665 CVE-2019-6190: Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BI Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
nvd
CVE-2016-1350HIGHCVSS 7.5fixed in m16kt61a2016-03-26
CVE-2016-1350 [HIGH] CWE-399 CVE-2016-1350: Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager all Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
nvd
CVE-2016-1344MEDIUMCVSS 5.9fixed in m16kt61a2016-03-26
CVE-2016-1344 [MEDIUM] CWE-399 CVE-2016-1344: The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote at The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
nvd
Lenovo Thinkcentre E75S Firmware vulnerabilities | cvebase