Home
MEDIUM: 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NMEDIUM: 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
Any version before 1.2.3.8
affected
Default status
unaffected
Any version before 1.4.11.4
affected
Description
An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.
Problem types
Product status
Any version before 1.2.3.8
Any version before 1.4.11.4
Credits
Lenovo thanks Aobo Wang(@M4x_1997) of Chaitin Security Research Lab for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-186929