cbcvebase.

Lenovo V50T-13Imb Firmware vulnerabilities

26 known vulnerabilities affecting lenovo/v50t-13imb_firmware.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM25

Vulnerabilities

Page 1 of 2
CVE-2022-48181P3HIGHCVSS 7.8fixed in o4hkt3aa2023-06-05
CVE-2022-48181 [HIGH] CWE-787 CVE-2022-48181: An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models cou An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
nvd
CVE-2023-43581P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43581 [MEDIUM] CWE-120 CVE-2023-43581: A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may all A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43577P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43577 [MEDIUM] CWE-120 CVE-2023-43577: A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43578P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43578 [MEDIUM] CWE-120 CVE-2023-43578: A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43575P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43575 [MEDIUM] CWE-120 CVE-2023-43575: A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43579P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43579 [MEDIUM] CWE-120 CVE-2023-43579: A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allo A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43573P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43573 [MEDIUM] CWE-120 CVE-2023-43573: A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43571P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43571 [MEDIUM] CWE-120 CVE-2023-43571: A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products tha A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43580P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43580 [MEDIUM] CWE-120 CVE-2023-43580: A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may a A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43569P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43569 [MEDIUM] CWE-120 CVE-2023-43569: A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43576P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43576 [MEDIUM] CWE-120 CVE-2023-43576: A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43567P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43567 [MEDIUM] CWE-120 CVE-2023-43567: A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products t A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
nvd
CVE-2023-43570P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-43570 [MEDIUM] CWE-20 CVE-2023-43570: A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may a A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.
nvd
CVE-2022-40137P4MEDIUMCVSS 6.7vo4hkt3aa2023-01-30
CVE-2022-40137 [MEDIUM] CWE-120 CVE-2022-40137: A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local acce A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
nvd
CVE-2023-45076P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-45076 [MEDIUM] CWE-125 CVE-2023-45076: A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attack A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
nvd
CVE-2023-45077P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-45077 [MEDIUM] CWE-125 CVE-2023-45077: A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attack A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
nvd
CVE-2023-45079P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-45079 [MEDIUM] CWE-125 CVE-2023-45079: A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attac A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
nvd
CVE-2023-45078P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-45078 [MEDIUM] CWE-125 CVE-2023-45078: A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a lo A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
nvd
CVE-2023-45075P4MEDIUMCVSS 6.7fixed in o4hkt3ca2023-11-08
CVE-2023-45075 [MEDIUM] CWE-125 CVE-2023-45075: A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local at A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
nvd
CVE-2021-3519P4MEDIUMCVSS 6.8fixed in o4hkt33a2021-11-12
CVE-2021-3519 [MEDIUM] CWE-287 CVE-2021-3519: A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to t A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
nvd