Metrics
- CVSS v4.0 N/A
- CVSS v3.1 9.8 Critical
- CVSS v3.0 N/A
- CVSS v2 10.0 Critical
- KEV no
- EPSS 0.04065
- SSVC no
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.04065.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
B50-10
Subscribe
B50-10 Firmware
Subscribe
Edge 15
Subscribe
Edge 15 Firmware
Subscribe
Flex 2 Pro-15
Subscribe
Flex 2 Pro-15 Firmware
Subscribe
Flex 3-1120
Subscribe
Flex 3-1120 Firmware
Subscribe
Flex 3-1470
Subscribe
Flex 3-1470 Firmware
Subscribe
Flex 3-1570
Subscribe
Flex 3-1570 Firmware
Subscribe
G40-80
Subscribe
G40-80 Firmware
Subscribe
G40-80m
Subscribe
G40-80m Firmware
Subscribe
G50-80
Subscribe
G50-80 Firmware
Subscribe
G50-80 Touch
Subscribe
G50-80 Touch Firmware
Subscribe
G50-80 Touch V3000
Subscribe
G50-80 Touch V3000 Firmware
Subscribe
G50-80m
Subscribe
G50-80m Firmware
Subscribe
G70-80
Subscribe
G70-80 Firmware
Subscribe
Ideapad 100-14iby
Subscribe
Ideapad 100-14iby Firmware
Subscribe
Ideapad 100-15iby
Subscribe
Ideapad 100-15iby Firmware
Subscribe
M40-35
Subscribe
M40-35 Firmware
Subscribe
S21e
Subscribe
S21e Firmware
Subscribe
S41-70
Subscribe
S41-70 Firmware
Subscribe
S435
Subscribe
S435 Firmware
Subscribe
U31-70
Subscribe
U31-70 Firmware
Subscribe
U41-70
Subscribe
U41-70 Firmware
Subscribe
Y40-80
Subscribe
Y40-80 Firmware
Subscribe
Yoga 3 11
Subscribe
Yoga 3 11 Firmware
Subscribe
Yoga 3 14
Subscribe
Yoga 3 14 Firmware
Subscribe
Z41-70
Subscribe
Z41-70 Firmware
Subscribe
Z51-70
Subscribe
Z51-70 Firmware
Subscribe
Z70-80
Subscribe
Z70-80 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5634 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T06:59:03.628Z
Reserved: 2015-07-27T00:00:00
Link: CVE-2015-5684
No data.
Status : Modified
Published: 2020-03-27T15:15:11.507
Modified: 2024-11-21T02:33:37.920
Link: CVE-2015-5684
No data.
OpenCVE Enrichment
No data.
EUVD