Please note: This website includes an accessibility system. Press Control-F11 to adjust the website to the visually impaired who are using a screen reader; Press Control-F10 to open an accessibility menu.

System Update Vulnerability

System Update Vulnerability

System Update Vulnerability

Lenovo Security Advisory: LEN-28093

Potential Impact:: Denial of Service

Severity: Medium

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2019-6175

Summary Description:

A denial of service vulnerability was reported in Lenovo System Update that could allow configuration files to be written to non-standard locations.

Mitigation Strategy for Customers (what you should do to protect yourself):

Upgrade to the Lenovo System Update version 5.07.0088 (or newer)

Product Impact:

  • Lenovo 3000 C100, C200, N100, N200, V100, V200
  • Lenovo 3000 J100, J105, J110, J115, J200, J200p, J205, S200, S200p, S205
  • All ThinkPad
  • All ThinkCentre
  • All ThinkStation
  • Lenovo V/B/K/E Series

Acknowledgement:

Lenovo would like to thank Eran Shimony at CyberArk Labs for reporting this issue.

Revision History:

Revision Date Description
1 2019-09-24 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.


Alias Id:LEN-28093
Document ID:PS500271
Original Publish Date:09/24/2019
Last Modified Date:09/24/2019