Improper Certificate Validation Vulnerability in Lenovo LADM Products
CVE-2024-6001

8.1HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
16 December 2024

Summary

An improper certificate validation vulnerability has been identified in Lenovo's LADM product line, allowing potential network attackers to manipulate update requests to a remote server. This security flaw could lead to elevated privilege code execution, posing significant risks to the integrity and confidentiality of systems utilizing these products. Organizations using affected versions are advised to apply necessary updates and review security configurations to mitigate this vulnerability.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.