Known vulnerabilities in Flash BIOS update for Windows 10 IOT - ThinkStation P5
Vendor:
Lenovo
Software CPE:
cpe:2.3:h:lenovo:flash_bios_update_for_windows_10_iot_-_thinkstation_p5:*:*:*:*:*:*:*:*
Website:
https://www.lenovo.com/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU113731 - Uncaught Exception CVE-2025-3770 |
CWE-248 | Low | - | 07.08.2025 |
SB2025080722 SB20250908112 SB2025092259 and 9 more |
||
| #VU113356 - Permissions, Privileges, and Access Controls CVE-2024-6364 |
CWE-264 | Low | - | 28.07.2025 |
SB2025072859 SB2025072860 |
||
| #VU111030 - Out-of-bounds read CVE-2025-2884 |
CWE-125 | Low | 16.11.20.1870 | 11.06.2025 |
SB2025061103 SB2025061303 SB2025072845 and 4 more |
||
| #VU104075 - Improper Access Control CVE-2024-30211 |
CWE-284 | Low | 16.11.20.1870 | 19.02.2025 |
SB2025022014 SB2025051632 SB2025052076 |
||
| #VU104071 - Improper Initialization CVE-2024-26021 |
CWE-665 | Low | 16.11.20.1870 | 19.02.2025 |
SB2025022014 SB2025051632 SB2025052076 |
||
| #VU104063 - Improper input validation CVE-2024-38307 |
CWE-20 | Medium | 16.11.20.1870 | 19.02.2025 |
SB2025022014 SB2025051632 SB2025052076 |