Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5mg-hr4q-j2cr

Опубликовано: 15 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data.

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data.

EPSS

Процентиль: 2%
0.00013
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 3.1
nvd
4 месяца назад

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.

EPSS

Процентиль: 2%
0.00013
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-295