Description
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data.
Problem types
CWE-295: Improper Certificate Validation
Product status
Any version before 25.7.0.21
Credits
Lenovo thanks Tomi Koski from Visma / Red Team for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-198727