CVE-2015-5684

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
27/03/2020
Last modified:
01/04/2020

Description

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:b50-10_firmware:*:*:*:*:*:*:*:* cccn13ww\(v1.02\) (excluding)
cpe:2.3:h:lenovo:b50-10:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_2_pro-15_firmware:*:*:*:*:*:*:*:* a9cn46ww (excluding)
cpe:2.3:h:lenovo:flex_2_pro-15:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:edge_15_firmware:*:*:*:*:*:*:*:* a9cn46ww (excluding)
cpe:2.3:h:lenovo:edge_15:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:edge_15_firmware:*:*:*:*:*:*:*:* b9cn17ww (excluding)
cpe:2.3:h:lenovo:edge_15:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_2_pro-15_firmware:*:*:*:*:*:*:*:* b9cn17ww (excluding)
cpe:2.3:h:lenovo:flex_2_pro-15:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_3-1470_firmware:*:*:*:*:*:*:*:* bdcn30ww (excluding)
cpe:2.3:h:lenovo:flex_3-1470:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_3-1570_firmware:*:*:*:*:*:*:*:* bdcn30ww (excluding)
cpe:2.3:h:lenovo:flex_3-1570:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:flex_3-1120_firmware:*:*:*:*:*:*:*:* c0cn25ww (excluding)


References to Advisories, Solutions, and Tools