Insecure HTTP Connection in Lenovo Service Bridge Affects User Data Transmission
CVE-2016-8230

7.5HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
4 June 2017

Summary

Lenovo Service Bridge, prior to version 4, utilizes an insecure HTTP connection to transmit sensitive information, such as system serial numbers, machine type and model, and product names to Lenovo's servers. This raises significant security concerns, as the data is susceptible to interception and misuse by malicious actors. Users are strongly advised to upgrade to the latest version of Lenovo Service Bridge to ensure secure communications and protect their sensitive information.

Affected Version(s)

Service Bridge Earlier than version 4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.