The client in Lenovo System Update prior to 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote malicious users to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
lenovo thinkvantage system update 3.13 |
||
lenovo thinkvantage system update |