Lucene search

K
cve[email protected]CVE-2015-2233
HistoryMay 12, 2015 - 7:59 p.m.

CVE-2015-2233

2015-05-1219:59:14
CWE-310
web.nvd.nist.gov
26
lenovo
system update
thinkvantage
cve-2015-2233
security
vulnerability
nvd

8.3 High

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.9%

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.

Affected configurations

NVD
Node
lenovosystem_updateRange5.06.0027

8.3 High

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.9%

Related for CVE-2015-2233