Thinkpad e490s firmware
This hub aggregates every CVE we track for Thinkpad e490s firmware, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
1
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM10HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 12 most recently published vulnerabilities affecting Thinkpad e490s firmware.
- CVE-2022-48189An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. 6.7
- CVE-2023-2290A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.6.4
- CVE-2022-40134An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.4.4
- CVE-2021-3718A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.4.3
- CVE-2019-18618Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical atta...6.0
- CVE-2019-18619Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave...7.8
- CVE-2020-8336Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.6.4
- CVE-2020-8323A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.6.4
- CVE-2020-8320An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.6.4
- CVE-2019-6188ThinkPad T460p and T470p BIOS Tamper Mechanism9.8
- CVE-2019-6172A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.6.4
- CVE-2019-6170A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.6.4
Product normalization is registry-driven with AI assist and human review. How it works