Home
MEDIUM: 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NMEDIUM: 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
Any version before 10.2501.20.0
affected
Default status
unaffected
Any version before 20.2506.39.0
affected
Description
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 10.2501.20.0
Any version before 20.2506.39.0
Credits
Lenovo thanks Bryan Alexander of Atredis Partners for reporting this issue.
References
support.lenovo.com/us/en/product_security/LEN-196648