Vantage
Vendor:
First CVE: Apr 14, 2020 · Active for 6 years
12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vantage over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2020
6 years ago
Most Recent CVE
Mar 11, 2026
139 days ago
CVE Severity & Scoring
Vantage12 CVEs
42%
58%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (91.7%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (8.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low10 (83.3%)
High1 (8.3%)
None1 (8.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1716HIGH An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbi | Mar 11, 2026 | 7.1 | 25 | NO | NO |
CVE-2026-1715HIGH An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbi | Mar 11, 2026 | 7.1 | 25 | NO | NO |
CVE-2020-8327HIGH A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that c | Apr 14, 2020 | 7.8 | 25 | NO | NO |
CVE-2025-13154MEDIUM An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file dele | Jan 14, 2026 | 5.5 | 23 | NO | NO |
CVE-2025-6232HIGH An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifyin | Jul 17, 2025 | 7.8 | 23 | NO | NO |
CVE-2025-6231HIGH An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifyin | Jul 17, 2025 | 7.8 | 23 | NO | NO |
CVE-2024-12673HIGH An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges | Feb 12, 2025 | 7.8 | 22 | NO | NO |
CVE-2023-6043HIGH A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges | Jan 19, 2024 | 7.8 | 22 | NO | NO |
CVE-2026-1717MEDIUM An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to termina | Mar 11, 2026 | 5.5 | 20 | NO | NO |
CVE-2023-6044MEDIUM A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitra | Jan 19, 2024 | 6.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Vantage
Top CWEs
Versions
No cataloged versions.