10
CVE-2015-5684
- EPSS 4.07%
- Veröffentlicht 27.03.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:33:37
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ B50-10 Firmware Version < cccn13ww\(v1.02\)
Lenovo ≫ Flex 2 Pro-15 Firmware Version < a9cn46ww
Lenovo ≫ Edge 15 Firmware Version < a9cn46ww
Lenovo ≫ Edge 15 Firmware Version < b9cn17ww
Lenovo ≫ Flex 2 Pro-15 Firmware Version < b9cn17ww
Lenovo ≫ Flex 3-1470 Firmware Version < bdcn30ww
Lenovo ≫ Flex 3-1570 Firmware Version < bdcn30ww
Lenovo ≫ Flex 3-1120 Firmware Version < c0cn25ww
Lenovo ≫ G40-80 Firmware Version < b0cn75ww
Lenovo ≫ G50-80 Firmware Version < b0cn75ww
Lenovo ≫ G50-80 Touch Firmware Version < b0cn75ww
Lenovo ≫ G50-80 Touch V3000 Firmware Version < b0cn75ww
Lenovo ≫ G40-80m Firmware Version < cbcn75ww
Lenovo ≫ G50-80m Firmware Version < cbcn75ww
Lenovo ≫ Ideapad 100-14iby Firmware Version < v1.02_\(cccn13ww\)
Lenovo ≫ Ideapad 100-15iby Firmware Version < v1.02_\(cccn13ww\)
Lenovo ≫ S21e Firmware Version < c4cn14ww\(v1.04\)
Lenovo ≫ S41-70 Firmware Version < bdcn30ww
Lenovo ≫ U41-70 Firmware Version < bdcn30ww
Lenovo ≫ S435 Firmware Version < bbcn15ww\(v1.06\)
Lenovo ≫ M40-35 Firmware Version < bbcn15ww\(v1.06\)
Lenovo ≫ U31-70 Firmware Version < afcn30ww\(v2.02\)
Lenovo ≫ Yoga 3 14 Firmware Version < bacn33ww
Lenovo ≫ Yoga 3 11 Firmware Version < b8cn30ww\(v2.08\)
Lenovo ≫ Y40-80 Firmware Version < b5cn36ww\(v2.02\)
Lenovo ≫ Z41-70 Firmware Version < c2cn18ww\(v1.04\)
Lenovo ≫ Z51-70 Firmware Version < c2cn18ww\(v1.04\)
Lenovo ≫ Z70-80 Firmware Version < abcn75ww
Lenovo ≫ G70-80 Firmware Version < abcn75ww
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 4.07% | 0.874 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.