CVE-2016-8230: Infoleak
Published Jun 3, 2017
·Updated
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
Affected Software
1 affected component
Lenovo Lenovo Service Bridge
Event History
Jun 3, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8230?
CVE-2016-8230 has a medium severity rating due to the use of insecure HTTP connections.
2
How do I fix CVE-2016-8230?
To fix CVE-2016-8230, upgrade to Lenovo Service Bridge version 4 or later.
3
What are the potential impacts of CVE-2016-8230?
CVE-2016-8230 could expose sensitive system information due to an insecure HTTP connection.
4
Which software is affected by CVE-2016-8230?
Lenovo Service Bridge versions before 4 are affected by CVE-2016-8230.
5
Is CVE-2016-8230 still a risk if I have updated my software?
No, if you have updated Lenovo Service Bridge to version 4 or later, CVE-2016-8230 is no longer a risk.