Lenovo's vulnerability footprint spans a very broad portfolio of consumer and commercial computing devices, from ThinkCentre desktop systems to IdeaCentre consumer machines, representing one of the largest device-manufacturer attack surfaces in the landscape. The exposure recurs across both firmware and host-level components and reflects weakness classes endemic to device firmware and system software: improper input validation, classic buffer overflows, incorrect default permissions, and unintended exposure of sensitive information. A meaningful share of the vendor's disclosures reach serious severity. Defenders managing Lenovo devices should prioritize firmware updates and restrict administrative access; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lenovo Group Ltd. over time
Of all the CVEs published by Lenovo Group Ltd. as a CNA, 70.7% affect products that Lenovo Group Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Lenovo Group Ltd., 84.4% are self-published by Lenovo Group Ltd. as a CNA.
Signals from CVEs in this vendor scope (417 CVEs).
417 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5638CRITICAL The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem | Mar 11, 2017 | 9.8 | 99 | YES | YES |
CVE-2022-3699HIGH
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45
that could allow a loc | Oct 25, 2023 | 7.8 | 38 | NO | YES |
CVE-2015-2219HIGH Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token w | May 12, 2015 | 7.2 | 36 | NO | YES |
CVE-2021-3897CRITICAL An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an | Apr 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-3849CRITICAL An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could | Apr 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2015-5684CRITICAL MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Leno | Mar 27, 2020 | 9.8 | 31 | NO | NO |
CVE-2017-17833CRITICAL OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnera | Apr 23, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-9082HIGH For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's | Sep 28, 2018 | 8.8 | 30 | NO | NO |
CVE-2018-9079CRITICAL For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, ad | Sep 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2026-13104HIGH A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code wit | Jul 16, 2026 | 7.3 | 29 | NO | NO |
Signals from CVEs in this vendor scope (417 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lenovo Group Ltd..
Media articles that mention a CVE ID that affects a product developed by Lenovo Group Ltd. — matched by CVE ID, not by vendor name.