First published: Sat Jun 03 2017(Updated: )
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Lenovo Service Bridge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-8229 is categorized as medium due to its potential to exploit cross-site request forgery.
To fix CVE-2016-8229, update Lenovo Service Bridge to a version later than 4.
Users and systems utilizing Lenovo Service Bridge versions prior to 4 are affected by CVE-2016-8229.
CVE-2016-8229 is a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2016-8229 can potentially be exploited by an attacker with access to the necessary local network environment.