CVE-2016-8231: High severity lenovo service bridge vulnerability
Published Jun 3, 2017
·Updated
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
Affected Software
1 affected component
Lenovo Lenovo Service Bridge
Event History
Jun 3, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8231?
CVE-2016-8231 is rated as a medium severity vulnerability.
2
How do I fix CVE-2016-8231?
To fix CVE-2016-8231, upgrade to Lenovo Service Bridge version 4 or later.
3
What kind of attack does CVE-2016-8231 enable?
CVE-2016-8231 allows an attacker to exploit the vulnerability to insert a forged code signing certificate.
4
Which versions of Lenovo Service Bridge are affected by CVE-2016-8231?
Lenovo Service Bridge versions prior to 4 are affected by CVE-2016-8231.
5
Is there a workaround for CVE-2016-8231?
There are no official workarounds for CVE-2016-8231; updating is recommended.