Lenovo Group Ltd.
First CVE: Nov 29, 2016Active for: 10 years
498
CVEs Published
More CVEs Published than 86% of tracked CNAs
45.3
Avg CVEs / Year
More Avg CVEs / Year than 83% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 31% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Lenovo Group Ltd. as a CNA, 70.7% affect products that Lenovo Group Ltd. develops as a vendor.
70.7%
29.3%
Self-reported: 352Third-party: 146
Of all the CVEs published that affect products developed by Lenovo Group Ltd., 84.4% are self-published by Lenovo Group Ltd. as a CNA.
84.4%
15.6%
Self-published: 352Published by other CNAs: 65
Trends Over Time
The number and severity of CVEs published by Lenovo Group Ltd. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2016
9 years ago
Most Recent CVE
Jul 16, 2026
8 days ago
Top CVEs
All CVEs published by Lenovo Group Ltd. as a CNA, regardless of affected vendor or product.
498 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3577HIGH An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized a | Nov 12, 2021 | 8.8 | 71 | NO | YES |
CVE-2022-3699HIGH
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45
that could allow a loc | Oct 25, 2023 | 7.8 | 38 | NO | YES |
CVE-2026-14371HIGH The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing re | Jul 16, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-5804HIGH An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file desc | May 19, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-6281HIGH A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands | May 13, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-9046HIGH A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when i | Jul 16, 2026 | 7.0 | 31 | NO | NO |
CVE-2026-6282HIGH A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access fi | May 13, 2026 | 8.1 | 31 | NO | NO |
CVE-2021-3897CRITICAL An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an | Apr 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-3849CRITICAL An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could | Apr 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-3460CRITICAL The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communic | Apr 13, 2021 | 9.8 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA498 CVEs
52%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local274 (55.0%)
Network168 (33.7%)
Unknown0 (0.0%)
Physical33 (6.6%)
Adjacent Network23 (4.6%)
Attack Complexity
Low438 (88.0%)
High60 (12.0%)
Unknown0 (0.0%)
User Interaction
None423 (84.9%)
Unknown0 (0.0%)
Required74 (14.9%)
Privileges Required
Low204 (41.0%)
High129 (25.9%)
None165 (33.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (498 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.2% of CVEs· 79th percentile
Nuclei
1 CVE
0.2% of CVEs· 72nd percentile
ExploitDB
1 CVE
0.2% of CVEs· 74th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Lenovo Group Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Lenovo Group Ltd. as a CNA — matched by CVE ID, not by organization name.