Lucene search

K
lenovoLenovoLENOVO:PS500345-LENOVO-VANTAGE-VULNERABILITY-NOSID
HistorySep 06, 2020 - 6:04 p.m.

Lenovo Vantage Vulnerability - Lenovo Support NL

2020-09-0618:04:42
support.lenovo.com
14

0.0004 Low

EPSS

Percentile

12.6%

**Lenovo Security Advisory:**LEN-38717

**Potential Impact:**Denial of Service

**Severity:**Medium

**Scope of Impact:**Lenovo-specific

**CVE Identifier:**CVE-2020-8346

Summary Description:

A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation that could allow configuration files to be written to non-standard locations.

Mitigation Strategy for Customers (what you should do to protect yourself):

To update Lenovo System Interface Foundation to version 1.1.19.5 or later, follow these steps:

Update Lenovo Vantage to the latest version from the Microsoft Store.

Re-launch Lenovo Vantage to complete the update.

To verify the Lenovo System Interface Foundation version:

1. Open Device Manager.

2. Expand System devices.

3. Right click System Interface Foundation V2 Device and select Properties.

4. Click the Driver tab.

5. Read the Driver Version.

Acknowledgement:

Lenovo thanks Samet Bekmezci for reporting this issue.

Revision History:

Revision Date Description
2 2020-09-10 Updated Mitigation section
1 2020-09-08 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an β€œas is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

0.0004 Low

EPSS

Percentile

12.6%

Related for LENOVO:PS500345-LENOVO-VANTAGE-VULNERABILITY-NOSID