Service bridge
This hub aggregates every CVE we track for Service bridge, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
2
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7CRITICAL2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
2024-072026-06
Latest CVEs
The 10 most recently published vulnerabilities affecting Service bridge.
- CVE-2026-1636A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.6.7
- CVE-2024-4696A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.7.5
- CVE-2019-6166A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.8.8
- CVE-2019-6168A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.9.8
- CVE-2019-6167A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.9.8
- CVE-2019-6169A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.7.5
- CVE-2016-8228In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.7.8
- CVE-2016-8231In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certific...7.5
- CVE-2016-8230In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.7.5
- CVE-2016-8229A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.8.8
Product normalization is registry-driven with AI assist and human review. How it works