CVE-2015-5684
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
27/03/2020
Last modified:
01/04/2020
Description
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lenovo:b50-10_firmware:*:*:*:*:*:*:*:* | cccn13ww\(v1.02\) (excluding) | |
| cpe:2.3:h:lenovo:b50-10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:flex_2_pro-15_firmware:*:*:*:*:*:*:*:* | a9cn46ww (excluding) | |
| cpe:2.3:h:lenovo:flex_2_pro-15:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:edge_15_firmware:*:*:*:*:*:*:*:* | a9cn46ww (excluding) | |
| cpe:2.3:h:lenovo:edge_15:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:edge_15_firmware:*:*:*:*:*:*:*:* | b9cn17ww (excluding) | |
| cpe:2.3:h:lenovo:edge_15:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:flex_2_pro-15_firmware:*:*:*:*:*:*:*:* | b9cn17ww (excluding) | |
| cpe:2.3:h:lenovo:flex_2_pro-15:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:flex_3-1470_firmware:*:*:*:*:*:*:*:* | bdcn30ww (excluding) | |
| cpe:2.3:h:lenovo:flex_3-1470:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:flex_3-1570_firmware:*:*:*:*:*:*:*:* | bdcn30ww (excluding) | |
| cpe:2.3:h:lenovo:flex_3-1570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:flex_3-1120_firmware:*:*:*:*:*:*:*:* | c0cn25ww (excluding) |
To consult the complete list of CPE names with products and versions, see this page



