Known vulnerabilities in Flash BIOS Update - ThinkStation P8

Vendor: Lenovo
Software CPE: cpe:2.3:h:lenovo:flash_bios_update_-_thinkstation_p8:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Flash BIOS Update - ThinkStation P8 Flash BIOS Update - ThinkStation P8 is affected by 11 known vulnerabilities: 11 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117652 - Insufficient Entropy
CVE-2025-62626
CWE-331 Low
No
No
S0GKT49A 24.10.2025 SB2025102470
SB2025120853
SB2025122706
and 21 more
#VU113731 - Uncaught Exception
CVE-2025-3770
CWE-248 Low
No
No
S0GKT49A 07.08.2025 SB2025080722
SB20250908112
SB2025092259
and 9 more
#VU113356 - Permissions, Privileges, and Access Controls
CVE-2024-6364
CWE-264 Low
No
No
- 28.07.2025 SB2025072859
SB2025072860
#VU112557 - Information Exposure through Microarchitectural State after Transient Execution
CVE-2024-36349
CWE-1342 Low
No
No
S0GKT42A 08.07.2025 SB2025070901
SB2025070903
SB2025072844
and 9 more
#VU112556 - Information Exposure through Microarchitectural State after Transient Execution
CVE-2024-36348
CWE-1342 Low
No
No
S0GKT42A 08.07.2025 SB2025070901
SB2025070903
SB2025072844
and 9 more
#VU112552 - Information Exposure through Microarchitectural State after Transient Execution
CVE-2024-36357
CWE-1342 Low
No
No
S0GKT42A 08.07.2025 SB2025070882
SB2025070903
SB2025070904
and 43 more
#VU112549 - Information Exposure through Microarchitectural State after Transient Execution
CVE-2024-36350
CWE-1342 Low
No
No
S0GKT42A 08.07.2025 SB2025070882
SB2025070903
SB2025070904
and 40 more
#VU111030 - Out-of-bounds read
CVE-2025-2884
CWE-125 Low
No
No
S0GKT42A 11.06.2025 SB2025061103
SB2025061303
SB2025072845
and 4 more
#VU109411 - Improper Access Control
CVE-2025-20100
CWE-284 Low
No
No
S0GKT42A 19.05.2025 SB2025051921
SB2025072844
#VU109410 - Insufficient Control Flow Management
CVE-2025-20004
CWE-691 Low
No
No
S0GKT42A 19.05.2025 SB2025051921
SB2025072844
#VU109409 - Improper restriction of software interfaces to hardware features
CVE-2024-48869
CWE-1256 Low
No
No
S0GKT42A 19.05.2025 SB2025051921
SB2025072844