2023-11-08
|
CVE-2023-39435
|
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321 IP Cameras
with firmware version M2.1.6.05 are
vulnerable to stack-based overflows. During the process of updating
certain settings sent from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
|
B8220_firmware, B8520_firmware, Cb3211_firmware, Cb3212_firmware, Cb5220_firmware, Cb6231_firmware, Cd321_firmware, Cf7201_firmware, Cf7300_firmware, Cf7500_firmware, Cf7501_firmware
|
9.8
|
|
2023-11-08
|
CVE-2023-3959
|
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 are
vulnerable to multiple instances of stack-based overflows. While
processing XML elements from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
|
B8220_firmware, B8520_firmware, Cb3211_firmware, Cb3212_firmware, Cb5220_firmware, Cb6231_firmware, Cd321_firmware, Cf7201_firmware, Cf7300_firmware, Cf7500_firmware, Cf7501_firmware
|
9.8
|
|
2023-11-08
|
CVE-2023-45225
|
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP CamerasĀ with firmware version M2.1.6.05 are
vulnerable to multiple instances of stack-based overflows. While parsing
certain XML elements from incoming network requests, the product does
not sufficiently check or validate allocated buffer size. This may lead
to remote code execution.
|
B8220_firmware, B8520_firmware, Cb3211_firmware, Cb3212_firmware, Cb5220_firmware, Cb6231_firmware, Cd321_firmware, Cf7201_firmware, Cf7300_firmware, Cf7500_firmware, Cf7501_firmware
|
9.8
|
|
2023-11-08
|
CVE-2023-4249
|
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 has a
command injection vulnerability in their implementation of their
binaries and handling of network requests.
|
B8220_firmware, B8520_firmware, Cb3211_firmware, Cb3212_firmware, Cb5220_firmware, Cb6231_firmware, Cd321_firmware, Cf7201_firmware, Cf7300_firmware, Cf7500_firmware, Cf7501_firmware
|
9.8
|
|
2023-11-08
|
CVE-2023-43573
|
A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
|
Ideacentre_3\-07ada05_firmware, Ideacentre_3\-07imb05_firmware, Ideacentre_5\-14acn6_firmware, Ideacentre_5\-14imb05_firmware, Ideacentre_5\-14iob6_firmware, Ideacentre_5_14iab7_firmware, Ideacentre_5_14irb8_firmware, Ideacentre_aio_3\-22iil5_firmware, Ideacentre_aio_3\-22imb05_firmware, Ideacentre_aio_3\-22itl6_firmware, Ideacentre_aio_3\-24alc6_firmware, Ideacentre_aio_3\-24iil5_firmware, Ideacentre_aio_3\-24imb05_firmware, Ideacentre_aio_3\-24itl6_firmware, Ideacentre_aio_3\-27imb05_firmware, Ideacentre_aio_3\-27itl6_firmware, Ideacentre_aio_3_21itl7_firmware, Ideacentre_aio_3_22iap7_firmware, Ideacentre_aio_3_24iap7_firmware, Ideacentre_aio_3_27iap7_firmware, Ideacentre_aio_5_24iah7_firmware, Ideacentre_aio_5_27iah7_firmware, Ideacentre_c5\-14imb05_firmware, Ideacentre_creator_5\-14iob6_firmware, Ideacentre_g5\-14amr05_firmware, Ideacentre_g5\-14imb05_firmware, Ideacentre_gaming_5\-14acn6_firmware, Ideacentre_gaming_5\-14iob6_firmware, Ideacentre_gaming_5_17acn7_firmware, Ideacentre_gaming_5_17iab7_firmware, Ideacentre_mini_5\-01imh05_firmware, Ideacentre_mini_5_01iaq7_firmware, Ideacentre_t540\-15ama_g_firmware, Legion_t5_26iab7_firmware, Legion_t5_26irb8_firmware, Legion_t7\-34iaz7_firmware, Legion_t7\-34imz5_firmware, Legion_t7_34irz8_firmware, Loq_17irb8_firmware, Thinkcentre_m625q_firmware, Thinkcentre_m630e_firmware, Thinkcentre_m70a_gen_3_firmware, Thinkcentre_m70c_firmware, Thinkcentre_m70q_firmware, Thinkcentre_m70q_gen_2_firmware, Thinkcentre_m70s_firmware, Thinkcentre_m70s_gen_3_firmware, Thinkcentre_m70t_firmware, Thinkcentre_m70t_gen_3_firmware, Thinkcentre_m75n_firmware, Thinkcentre_m75q_gen_2_firmware, Thinkcentre_m75s_gen_2_firmware, Thinkcentre_m75t_gen_2_firmware, Thinkcentre_m80q_firmware, Thinkcentre_m80q_gen_3_firmware, Thinkcentre_m80s_firmware, Thinkcentre_m80s_gen_3_firmware, Thinkcentre_m80t_firmware, Thinkcentre_m80t_gen_3_firmware, Thinkcentre_m90a_firmware, Thinkcentre_m90a_gen_2_firmware, Thinkcentre_m90a_gen_3_firmware, Thinkcentre_m90a_pro_gen_3_firmware, Thinkcentre_m90q_gen_2_firmware, Thinkcentre_m90q_gen_3_firmware, Thinkcentre_m90q_tiny_firmware, Thinkcentre_m90s_firmware, Thinkcentre_m90s_gen_3_firmware, Thinkcentre_m90t_firmware, Thinkcentre_m90t_gen_3_firmware, Thinkcentre_m920z_all\-In\-One_firmware, Thinkcentre_neo_30a_22_gen_3_firmware, Thinkcentre_neo_30a_22_gen_4_firmware, Thinkcentre_neo_30a_24_gen_3_firmware, Thinkcentre_neo_30a_24_gen_4_firmware, Thinkcentre_neo_30a_27_gen_3_firmware, Thinkcentre_neo_30a_27_gen_4_firmware, Thinkcentre_neo_50a_24_gen_3_firmware, Thinkcentre_neo_50a_24_gen_4_firmware, Thinkcentre_neo_50t_gen_3_firmware, Thinkcentre_neo_70t_gen_3_firmware, Thinkedge_se30_firmware, Thinkstation_p320_workstation_firmware, Thinkstation_p330_workstation_2nd_gen_firmware, Thinkstation_p330_workstation_firmware, Thinkstation_p340_tiny_workstation_firmware, Thinkstation_p340_workstation_firmware, Thinkstation_p348_workstation_firmware, Thinkstation_p350_tiny_workstation_firmware, Thinkstation_p350_workstation_firmware, Thinkstation_p358_workstation_firmware, Thinkstation_p360_tiny_workstation_firmware, Thinkstation_p360_ultra_workstation_firmware, Thinkstation_p360_workstation_firmware, Thinkstation_p520_workstation_firmware, Thinkstation_p520c_workstation_firmware, Thinkstation_p720_workstation_firmware, Thinkstation_p920_workstation_firmware, V30a\-22iml_firmware, V30a\-22itl_firmware, V30a\-24iml_firmware, V30a\-24itl_firmware, V50a\-22imb_firmware, V50a\-24imb_firmware, V50s\-07imb_firmware, V50t\-13imb_firmware, V50t\-13imh_firmware, V50t\-13iob_firmware, V55t_gen_2_13acn_firmware, Yoga_aio_7\-27arh6_firmware, Yoga_aio_7_27arh7_firmware
|
6.7
|
|
2023-11-08
|
CVE-2023-43571
|
A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
|
Ideacentre_3\-07ada05_firmware, Ideacentre_3\-07imb05_firmware, Ideacentre_5\-14acn6_firmware, Ideacentre_5\-14imb05_firmware, Ideacentre_5\-14iob6_firmware, Ideacentre_5_14iab7_firmware, Ideacentre_5_14irb8_firmware, Ideacentre_aio_3\-22iil5_firmware, Ideacentre_aio_3\-22imb05_firmware, Ideacentre_aio_3\-22itl6_firmware, Ideacentre_aio_3\-24alc6_firmware, Ideacentre_aio_3\-24iil5_firmware, Ideacentre_aio_3\-24imb05_firmware, Ideacentre_aio_3\-24itl6_firmware, Ideacentre_aio_3\-27imb05_firmware, Ideacentre_aio_3\-27itl6_firmware, Ideacentre_aio_3_21itl7_firmware, Ideacentre_aio_3_22iap7_firmware, Ideacentre_aio_3_24iap7_firmware, Ideacentre_aio_3_27iap7_firmware, Ideacentre_aio_5_24iah7_firmware, Ideacentre_aio_5_27iah7_firmware, Ideacentre_c5\-14imb05_firmware, Ideacentre_creator_5\-14iob6_firmware, Ideacentre_g5\-14amr05_firmware, Ideacentre_g5\-14imb05_firmware, Ideacentre_gaming_5\-14acn6_firmware, Ideacentre_gaming_5\-14iob6_firmware, Ideacentre_gaming_5_17acn7_firmware, Ideacentre_gaming_5_17iab7_firmware, Ideacentre_mini_5\-01imh05_firmware, Ideacentre_mini_5_01iaq7_firmware, Ideacentre_t540\-15ama_g_firmware, Legion_t5_26iab7_firmware, Legion_t5_26irb8_firmware, Legion_t7\-34iaz7_firmware, Legion_t7\-34imz5_firmware, Legion_t7_34irz8_firmware, Loq_17irb8_firmware, Thinkcentre_m625q_firmware, Thinkcentre_m630e_firmware, Thinkcentre_m70a_gen_3_firmware, Thinkcentre_m70c_firmware, Thinkcentre_m70q_firmware, Thinkcentre_m70q_gen_2_firmware, Thinkcentre_m70s_firmware, Thinkcentre_m70s_gen_3_firmware, Thinkcentre_m70t_firmware, Thinkcentre_m70t_gen_3_firmware, Thinkcentre_m75n_firmware, Thinkcentre_m75q_gen_2_firmware, Thinkcentre_m75s_gen_2_firmware, Thinkcentre_m75t_gen_2_firmware, Thinkcentre_m80q_firmware, Thinkcentre_m80q_gen_3_firmware, Thinkcentre_m80s_firmware, Thinkcentre_m80s_gen_3_firmware, Thinkcentre_m80t_firmware, Thinkcentre_m80t_gen_3_firmware, Thinkcentre_m90a_firmware, Thinkcentre_m90a_gen_2_firmware, Thinkcentre_m90a_gen_3_firmware, Thinkcentre_m90a_pro_gen_3_firmware, Thinkcentre_m90q_gen_2_firmware, Thinkcentre_m90q_gen_3_firmware, Thinkcentre_m90q_tiny_firmware, Thinkcentre_m90s_firmware, Thinkcentre_m90s_gen_3_firmware, Thinkcentre_m90t_firmware, Thinkcentre_m90t_gen_3_firmware, Thinkcentre_m920z_all\-In\-One_firmware, Thinkcentre_neo_30a_22_gen_3_firmware, Thinkcentre_neo_30a_22_gen_4_firmware, Thinkcentre_neo_30a_24_gen_3_firmware, Thinkcentre_neo_30a_24_gen_4_firmware, Thinkcentre_neo_30a_27_gen_3_firmware, Thinkcentre_neo_30a_27_gen_4_firmware, Thinkcentre_neo_50a_24_gen_3_firmware, Thinkcentre_neo_50a_24_gen_4_firmware, Thinkcentre_neo_50t_gen_3_firmware, Thinkcentre_neo_70t_gen_3_firmware, Thinkedge_se30_firmware, Thinkstation_p320_workstation_firmware, Thinkstation_p330_workstation_2nd_gen_firmware, Thinkstation_p330_workstation_firmware, Thinkstation_p340_tiny_workstation_firmware, Thinkstation_p340_workstation_firmware, Thinkstation_p348_workstation_firmware, Thinkstation_p350_tiny_workstation_firmware, Thinkstation_p350_workstation_firmware, Thinkstation_p358_workstation_firmware, Thinkstation_p360_tiny_workstation_firmware, Thinkstation_p360_ultra_workstation_firmware, Thinkstation_p360_workstation_firmware, Thinkstation_p520_workstation_firmware, Thinkstation_p520c_workstation_firmware, Thinkstation_p720_workstation_firmware, Thinkstation_p920_workstation_firmware, V30a\-22iml_firmware, V30a\-22itl_firmware, V30a\-24iml_firmware, V30a\-24itl_firmware, V50a\-22imb_firmware, V50a\-24imb_firmware, V50s\-07imb_firmware, V50t\-13imb_firmware, V50t\-13imh_firmware, V50t\-13iob_firmware, V55t_gen_2_13acn_firmware, Yoga_aio_7\-27arh6_firmware, Yoga_aio_7_27arh7_firmware
|
6.7
|
|
2023-11-08
|
CVE-2023-43577
|
A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
|
Ideacentre_3\-07ada05_firmware, Ideacentre_3\-07imb05_firmware, Ideacentre_5\-14acn6_firmware, Ideacentre_5\-14imb05_firmware, Ideacentre_5\-14iob6_firmware, Ideacentre_5_14iab7_firmware, Ideacentre_5_14irb8_firmware, Ideacentre_aio_3\-22iil5_firmware, Ideacentre_aio_3\-22imb05_firmware, Ideacentre_aio_3\-22itl6_firmware, Ideacentre_aio_3\-24alc6_firmware, Ideacentre_aio_3\-24iil5_firmware, Ideacentre_aio_3\-24imb05_firmware, Ideacentre_aio_3\-24itl6_firmware, Ideacentre_aio_3\-27imb05_firmware, Ideacentre_aio_3\-27itl6_firmware, Ideacentre_aio_3_21itl7_firmware, Ideacentre_aio_3_22iap7_firmware, Ideacentre_aio_3_24iap7_firmware, Ideacentre_aio_3_27iap7_firmware, Ideacentre_aio_5_24iah7_firmware, Ideacentre_aio_5_27iah7_firmware, Ideacentre_c5\-14imb05_firmware, Ideacentre_creator_5\-14iob6_firmware, Ideacentre_g5\-14amr05_firmware, Ideacentre_g5\-14imb05_firmware, Ideacentre_gaming_5\-14acn6_firmware, Ideacentre_gaming_5\-14iob6_firmware, Ideacentre_gaming_5_17acn7_firmware, Ideacentre_gaming_5_17iab7_firmware, Ideacentre_mini_5\-01imh05_firmware, Ideacentre_mini_5_01iaq7_firmware, Ideacentre_t540\-15ama_g_firmware, Legion_t5_26iab7_firmware, Legion_t5_26irb8_firmware, Legion_t7\-34iaz7_firmware, Legion_t7\-34imz5_firmware, Legion_t7_34irz8_firmware, Loq_17irb8_firmware, Thinkcentre_m625q_firmware, Thinkcentre_m630e_firmware, Thinkcentre_m70a_gen_3_firmware, Thinkcentre_m70c_firmware, Thinkcentre_m70q_firmware, Thinkcentre_m70q_gen_2_firmware, Thinkcentre_m70s_firmware, Thinkcentre_m70s_gen_3_firmware, Thinkcentre_m70t_firmware, Thinkcentre_m70t_gen_3_firmware, Thinkcentre_m75n_firmware, Thinkcentre_m75q_gen_2_firmware, Thinkcentre_m75s_gen_2_firmware, Thinkcentre_m75t_gen_2_firmware, Thinkcentre_m80q_firmware, Thinkcentre_m80q_gen_3_firmware, Thinkcentre_m80s_firmware, Thinkcentre_m80s_gen_3_firmware, Thinkcentre_m80t_firmware, Thinkcentre_m80t_gen_3_firmware, Thinkcentre_m90a_firmware, Thinkcentre_m90a_gen_2_firmware, Thinkcentre_m90a_gen_3_firmware, Thinkcentre_m90a_pro_gen_3_firmware, Thinkcentre_m90q_gen_2_firmware, Thinkcentre_m90q_gen_3_firmware, Thinkcentre_m90q_tiny_firmware, Thinkcentre_m90s_firmware, Thinkcentre_m90s_gen_3_firmware, Thinkcentre_m90t_firmware, Thinkcentre_m90t_gen_3_firmware, Thinkcentre_m920z_all\-In\-One_firmware, Thinkcentre_neo_30a_22_gen_3_firmware, Thinkcentre_neo_30a_22_gen_4_firmware, Thinkcentre_neo_30a_24_gen_3_firmware, Thinkcentre_neo_30a_24_gen_4_firmware, Thinkcentre_neo_30a_27_gen_3_firmware, Thinkcentre_neo_30a_27_gen_4_firmware, Thinkcentre_neo_50a_24_gen_3_firmware, Thinkcentre_neo_50a_24_gen_4_firmware, Thinkcentre_neo_50t_gen_3_firmware, Thinkcentre_neo_70t_gen_3_firmware, Thinkedge_se30_firmware, Thinkstation_p320_workstation_firmware, Thinkstation_p330_workstation_2nd_gen_firmware, Thinkstation_p330_workstation_firmware, Thinkstation_p340_tiny_workstation_firmware, Thinkstation_p340_workstation_firmware, Thinkstation_p348_workstation_firmware, Thinkstation_p350_tiny_workstation_firmware, Thinkstation_p350_workstation_firmware, Thinkstation_p358_workstation_firmware, Thinkstation_p360_tiny_workstation_firmware, Thinkstation_p360_ultra_workstation_firmware, Thinkstation_p360_workstation_firmware, Thinkstation_p520_workstation_firmware, Thinkstation_p520c_workstation_firmware, Thinkstation_p720_workstation_firmware, Thinkstation_p920_workstation_firmware, V30a\-22iml_firmware, V30a\-22itl_firmware, V30a\-24iml_firmware, V30a\-24itl_firmware, V50a\-22imb_firmware, V50a\-24imb_firmware, V50s\-07imb_firmware, V50t\-13imb_firmware, V50t\-13imh_firmware, V50t\-13iob_firmware, V55t_gen_2_13acn_firmware, Yoga_aio_7\-27arh6_firmware, Yoga_aio_7_27arh7_firmware
|
6.7
|
|