First published: Sat Jun 03 2017(Updated: )
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Lenovo Service Bridge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8230 has a medium severity rating due to the use of insecure HTTP connections.
To fix CVE-2016-8230, upgrade to Lenovo Service Bridge version 4 or later.
CVE-2016-8230 could expose sensitive system information due to an insecure HTTP connection.
Lenovo Service Bridge versions before 4 are affected by CVE-2016-8230.
No, if you have updated Lenovo Service Bridge to version 4 or later, CVE-2016-8230 is no longer a risk.