Description
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection.
Problem types
CWE-347: Improper Verification of Cryptographic Signature
Product status
Any version before 4.8.0
Any version before 4.8.0
Credits
Lenovo thanks Mickey Shkatov and Jesse Michael of Eclypsium for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-194466