CVE-2026-10587
MEDIUMLenovo Yoga Pro 7 15IPH11 Bios - Out-of-Bounds Access
Title source: ruleDescription
A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://support.lenovo.com/us/en/product_security/LEN-220440
Scores
CVSS v3
6.0
EPSS
0.0010
EPSS Percentile
1.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-787
Status
published
Products (50)
Lenovo/IdeaPad 5 15ABA7 BIOS
< KACN29WW
Lenovo/IdeaPad Pro 5 16AGP11 BIOS
< T8CN19WW
Lenovo/IdeaPad Pro 5 16ASP10 BIOS
< R1CN24WW
Lenovo/IdeaPad Pro 5 16IAH10 BIOS
< PZCN27WW
Lenovo/IdeaPad Pro 5 16IMH9 BIOS
< MECN68WW
Lenovo/IdeaPad Pro 5 16IPH11 BIOS
< S4CN62WW
Lenovo/IdeaPad Pro 5 16IRH8 BIOS
< KZCN46WW
Lenovo/IdeaPad Slim 3 14ITN9 BIOS
< QUCN20WW
Lenovo/IdeaPad Slim 3 15AMN8 BIOS
< L1CN51WW
Lenovo/IdeaPad Slim 3 16ARP10 BIOS
< QBCN30WW
... and 40 more
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026