peter bassill · operator
$ cve CVE-2015-5684 JSON

CVE-2015-5684

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.69% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2020-03-27
Last modified2026-06-17

Affected (40)

VendorProduct
lenovob50-10
lenovob50-10 firmware
lenovoedge 15
lenovoedge 15 firmware
lenovoflex 2 pro-15
lenovoflex 2 pro-15 firmware
lenovoflex 3-1120
lenovoflex 3-1120 firmware
lenovoflex 3-1470
lenovoflex 3-1470 firmware
lenovoflex 3-1570
lenovoflex 3-1570 firmware
lenovog40-80
lenovog40-80 firmware
lenovog40-80m
lenovog40-80m firmware
lenovog50-80
lenovog50-80 firmware
lenovog50-80 touch
lenovog50-80 touch firmware
lenovog50-80 touch v3000
lenovog50-80 touch v3000 firmware
lenovog50-80m
lenovog50-80m firmware
lenovoideapad 100-14iby
lenovoideapad 100-14iby firmware
lenovoideapad 100-15iby
lenovoideapad 100-15iby firmware
lenovom40-35
lenovom40-35 firmware
lenovos21e
lenovos21e firmware
lenovos41-70
lenovos41-70 firmware
lenovos435
lenovos435 firmware
lenovou31-70
lenovou31-70 firmware
lenovou41-70
lenovou41-70 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD