5.1
CVSSv2

CVE-2008-3249

Published: 21/07/2008 Updated: 08/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The client in Lenovo System Update prior to 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote malicious users to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo thinkvantage system update 3.13

lenovo thinkvantage system update