Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2pg-h6p9-9j46

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

EPSS

Процентиль: 79%
0.01309
Низкий

Связанные уязвимости

nvd
больше 17 лет назад

The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

EPSS

Процентиль: 79%
0.01309
Низкий