Lenovo Service Bridge Vulnerabilities

Lenovo Service Bridge Vulnerabilities

Lenovo Service Bridge Vulnerabilities

Lenovo Security Advisory: LEN-27725

Potential Impact: Remote code execution

Severity: High

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2019-6166,CVE-2019-6167,CVE-2019-6168, CVE-2019-6169

Summary Description:

Vulnerabilities reported in Lenovo Service Bridge could allow remote code execution or unencrypted downloads over FTP.

Mitigation Strategy for Customers (what you should do to protect yourself):

Upgrade to the Lenovo Service Bridge version 4.1.0.1 (or later).

If you previously installed Lenovo Service Bridge, the update will be performed automatically. To confirm the version installed, go to Apps & Settings.

Product Impact:

IdeaPad, IdeaCentre, Lenovo Tab (Windows), ThinkCentre, ThinkPad, ThinkStation, Yoga

Acknowledgement:

Lenovo would like to thank Bill Demirkapi for reporting this issue.

Revision History:

Revision Date Description
1 2019-06-25 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.


Alias Id:LEN-27725
Document ID:PS500260
Original Publish Date:06/24/2019
Last Modified Date:06/25/2019