Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lenovo Group Ltd.

First CVE: Mar 7, 2007Active for: 19 yearsTotal CVEs: 417
41.6
VTI Score
High

Lenovo's vulnerability footprint spans a very broad portfolio of consumer and commercial computing devices, from ThinkCentre desktop systems to IdeaCentre consumer machines, representing one of the largest device-manufacturer attack surfaces in the landscape. The exposure recurs across both firmware and host-level components and reflects weakness classes endemic to device firmware and system software: improper input validation, classic buffer overflows, incorrect default permissions, and unintended exposure of sensitive information. A meaningful share of the vendor's disclosures reach serious severity. Defenders managing Lenovo devices should prioritize firmware updates and restrict administrative access; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
417
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Lenovo Group Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2007
19 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

Self-Reporting Analysis

Of all the CVEs published by Lenovo Group Ltd. as a CNA, 70.7% affect products that Lenovo Group Ltd. develops as a vendor.

70.7%
29.3%
Self-reported: 352 (70.7%)
Third-party: 146 (29.3%)

Of all the CVEs published that affect products developed by Lenovo Group Ltd., 84.4% are self-published by Lenovo Group Ltd. as a CNA.

84.4%
15.6%
Self-published: 352 (84.4%)
Other CNAs: 65 (15.6%)

Products(4,490 total)

Top CVEs

Signals from CVEs in this vendor scope (417 CVEs).

417 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5638CRITICAL
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem
Mar 11, 20179.899YESYES
CVE-2022-3699HIGH
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a loc
Oct 25, 20237.838NOYES
CVE-2015-2219HIGH
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token w
May 12, 20157.236NOYES
CVE-2021-3897CRITICAL
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an
Apr 22, 20229.831NONO
CVE-2021-3849CRITICAL
An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could
Apr 22, 20229.831NONO
CVE-2015-5684CRITICAL
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Leno
Mar 27, 20209.831NONO
CVE-2017-17833CRITICAL
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnera
Apr 23, 20189.831NONO
CVE-2018-9082HIGH
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's
Sep 28, 20188.830NONO
CVE-2018-9079CRITICAL
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, ad
Sep 28, 20189.830NONO
CVE-2026-13104HIGH
A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code wit
Jul 16, 20267.329NONO
View all 417 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products417 CVEs
49%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local217 (52.0%)
Network143 (34.3%)
Unknown21 (5.0%)
Physical25 (6.0%)
Adjacent Network11 (2.6%)
Attack Complexity
Low344 (82.5%)
High52 (12.5%)
Unknown21 (5.0%)
User Interaction
None356 (85.4%)
Unknown21 (5.0%)
Required40 (9.6%)
Privileges Required
Low164 (39.3%)
High99 (23.7%)
None133 (31.9%)
Unknown21 (5.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (417 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· 99th percentile
Metasploit
3 CVEs
0.7% of CVEs· 97th percentile
Nuclei
1 CVE
0.2% of CVEs· 95th percentile
ExploitDB
4 CVEs
1.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lenovo Group Ltd..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lenovo Group Ltd. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lenovo Group Ltd.'s Products

View all 7 CNAs →

Top CWEs