Lenovo Update
2984Warning Date
Severity Level
Warning Number
Target Sector
10 September, 2020
● High
2020-1753
All
Description:
Lenovo has released a security update to address several vulnerabilities in the following products:
- Desktop
- Desktop - All in One
- Lenovo Notebook
- Storage
- ThinkAgile
- ThinkBooks
- ThinkPad
- ThinkStation
- ThinkSystem
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
- Denial of Service (DoS)
- Information Disclosure
- Code execution
- Cross-site scripting (XSS) )
Best practice and Recommendations:
The CERT team encourages users to review Lenovo security advisory and apply the necessary updates:
- https://support.lenovo.com/us/en/product_security/LEN-37550
- https://support.lenovo.com/us/en/product_security/LEN-43116
- https://support.lenovo.com/us/en/product_security/LEN-44717
- https://support.lenovo.com/us/en/product_security/LEN-42150
- https://support.lenovo.com/us/en/product_security/LEN-38385
- https://support.lenovo.com/us/en/product_security/LEN-41856
- https://support.lenovo.com/us/en/product_security/LEN-38717
- https://support.lenovo.com/us/en/product_security/LEN-42153