Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-5684


MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.


Published

2020-03-27T15:15:11.507

Last Modified

2024-11-21T02:33:37.920

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo b50-10_firmware < cccn13ww\(v1.02\) Yes
Hardware lenovo b50-10 - No
Operating System lenovo flex_2_pro-15_firmware < a9cn46ww Yes
Hardware lenovo flex_2_pro-15 - No
Operating System lenovo edge_15_firmware < a9cn46ww Yes
Hardware lenovo edge_15 - No
Operating System lenovo edge_15_firmware < b9cn17ww Yes
Hardware lenovo edge_15 - No
Operating System lenovo flex_2_pro-15_firmware < b9cn17ww Yes
Hardware lenovo flex_2_pro-15 - No
Operating System lenovo flex_3-1470_firmware < bdcn30ww Yes
Hardware lenovo flex_3-1470 - No
Operating System lenovo flex_3-1570_firmware < bdcn30ww Yes
Hardware lenovo flex_3-1570 - No
Operating System lenovo flex_3-1120_firmware < c0cn25ww Yes
Hardware lenovo flex_3-1120 - No
Operating System lenovo g40-80_firmware < b0cn75ww Yes
Hardware lenovo g40-80 - No
Operating System lenovo g50-80_firmware < b0cn75ww Yes
Hardware lenovo g50-80 - No
Operating System lenovo g50-80_touch_firmware < b0cn75ww Yes
Hardware lenovo g50-80_touch - No
Operating System lenovo g50-80_touch_v3000_firmware < b0cn75ww Yes
Hardware lenovo g50-80_touch_v3000 - No
Operating System lenovo g40-80m_firmware < cbcn75ww Yes
Hardware lenovo g40-80m - No
Operating System lenovo g50-80m_firmware < cbcn75ww Yes
Hardware lenovo g50-80m - No
Operating System lenovo ideapad_100-14iby_firmware < v1.02_\(cccn13ww\) Yes
Hardware lenovo ideapad_100-14iby - No
Operating System lenovo ideapad_100-15iby_firmware < v1.02_\(cccn13ww\) Yes
Hardware lenovo ideapad_100-15iby - No
Operating System lenovo s21e_firmware < c4cn14ww\(v1.04\) Yes
Hardware lenovo s21e - No
Operating System lenovo s41-70_firmware < bdcn30ww Yes
Hardware lenovo s41-70 - No
Operating System lenovo u41-70_firmware < bdcn30ww Yes
Hardware lenovo u41-70 - No
Operating System lenovo s435_firmware < bbcn15ww\(v1.06\) Yes
Hardware lenovo s435 - No
Operating System lenovo m40-35_firmware < bbcn15ww\(v1.06\) Yes
Hardware lenovo m40-35 - No
Operating System lenovo u31-70_firmware < afcn30ww\(v2.02\) Yes
Hardware lenovo u31-70 - No
Operating System lenovo yoga_3_14_firmware < bacn33ww Yes
Hardware lenovo yoga_3_14 - No
Operating System lenovo yoga_3_11_firmware < b8cn30ww\(v2.08\) Yes
Hardware lenovo yoga_3_11 - No
Operating System lenovo y40-80_firmware < b5cn36ww\(v2.02\) Yes
Hardware lenovo y40-80 - No
Operating System lenovo z41-70_firmware < c2cn18ww\(v1.04\) Yes
Hardware lenovo z41-70 - No
Operating System lenovo z51-70_firmware < c2cn18ww\(v1.04\) Yes
Hardware lenovo z51-70 - No
Operating System lenovo z70-80_firmware < abcn75ww Yes
Hardware lenovo z70-80 - No
Operating System lenovo g70-80_firmware < abcn75ww Yes
Hardware lenovo g70-80 - No

References