Vulnerability Description
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | B50-10 Firmware | < cccn13ww\(v1.02\) |
| Lenovo | B50-10 | - |
| Lenovo | Flex 2 Pro-15 Firmware | < a9cn46ww |
| Lenovo | Flex 2 Pro-15 | - |
| Lenovo | Edge 15 Firmware | < a9cn46ww |
| Lenovo | Edge 15 | - |
| Lenovo | Flex 3-1470 Firmware | < bdcn30ww |
| Lenovo | Flex 3-1470 | - |
| Lenovo | Flex 3-1570 Firmware | < bdcn30ww |
| Lenovo | Flex 3-1570 | - |
| Lenovo | Flex 3-1120 Firmware | < c0cn25ww |
| Lenovo | Flex 3-1120 | - |
| Lenovo | G40-80 Firmware | < b0cn75ww |
| Lenovo | G40-80 | - |
| Lenovo | G50-80 Firmware | < b0cn75ww |
| Lenovo | G50-80 | - |
| Lenovo | G50-80 Touch Firmware | < b0cn75ww |
| Lenovo | G50-80 Touch | - |
| Lenovo | G50-80 Touch V3000 Firmware | < b0cn75ww |
| Lenovo | G50-80 Touch V3000 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/lse_bios_notebookVendor Advisory
- https://support.lenovo.com/us/en/product_security/lse_bios_notebookVendor Advisory
FAQ
What is CVE-2015-5684?
CVE-2015-5684 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (L...
How severe is CVE-2015-5684?
CVE-2015-5684 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-5684?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo B50-10 Firmware, Lenovo B50-10, Lenovo Flex 2 Pro-15 Firmware, Lenovo Flex 2 Pro-15, Lenovo Edge 15 Firmware.