Back

CVE-2015-5684

CRITICAL

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.

Published: Mar 27, 2020 Modified: Jun 17, 2026
CWE-120

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (29)

Vendor Product Version
lenovo b50-10_firmware * < cccn13ww\(v1.02\)
lenovo flex_2_pro-15_firmware * < a9cn46ww
lenovo edge_15_firmware * < a9cn46ww
lenovo edge_15_firmware * < b9cn17ww
lenovo flex_2_pro-15_firmware * < b9cn17ww
lenovo flex_3-1470_firmware * < bdcn30ww
lenovo flex_3-1570_firmware * < bdcn30ww
lenovo flex_3-1120_firmware * < c0cn25ww
lenovo g40-80_firmware * < b0cn75ww
lenovo g50-80_firmware * < b0cn75ww
lenovo g50-80_touch_firmware * < b0cn75ww
lenovo g50-80_touch_v3000_firmware * < b0cn75ww
lenovo g40-80m_firmware * < cbcn75ww
lenovo g50-80m_firmware * < cbcn75ww
lenovo ideapad_100-14iby_firmware * < v1.02_\(cccn13ww\)
lenovo ideapad_100-15iby_firmware * < v1.02_\(cccn13ww\)
lenovo s21e_firmware * < c4cn14ww\(v1.04\)
lenovo s41-70_firmware * < bdcn30ww
lenovo u41-70_firmware * < bdcn30ww
lenovo s435_firmware * < bbcn15ww\(v1.06\)

…and 9 more

GitHub Security Advisory GHSA-xp5w-3gmw-7xvj

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.69%

Top 11% most likely to be exploited

Threat Score 40.3 / 100

Data Sources

NVD EPSS GitHub