Home
HIGH: 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 9.0.2530.1027
affected
Default status
unaffected
Any version before 5.1.140.9262
affected
Default status
unaffected
Any version before 9.0.6.9111
affected
Default status
unaffected
Any version before 2.0.21
affected
Description
A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.
Problem types
CWE-295: Improper Certificate Validation
Product status
Any version before 9.0.2530.1027
Any version before 5.1.140.9262
Any version before 9.0.6.9111
Any version before 2.0.21
Credits
Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue.
References
iknow.lenovo.com.cn/detail/434328