First published: Tue Jun 25 2019(Updated: )
A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <5.07.0084 | |
Lenovo C200 | ||
Lenovo E Series | ||
Lenovo J100 | ||
Lenovo J105 | ||
Lenovo J110 | ||
Lenovo J115 | ||
Lenovo J200 | ||
Lenovo J200p | ||
Lenovo J205 | ||
Lenovo K Series | ||
Lenovo N100 | ||
Lenovo N200 | ||
Lenovo S200 | ||
Lenovo S200p | ||
Lenovo S205 | ||
Lenovo Thinkcentre | ||
Lenovo ThinkPad | ||
Lenovo Thinkstation | ||
Lenovo V Series | ||
Lenovo V100 | ||
Lenovo V200 |
Upgrade to the Lenovo System Update version 5.07.0084 (or newer).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6163 is a denial of service vulnerability in Lenovo System Update before version 5.07.0084.
The severity of CVE-2019-6163 is high, with a CVSS score of 7.5.
CVE-2019-6163 could allow service log files to be written to non-standard locations in Lenovo System Update before version 5.07.0084.
To fix CVE-2019-6163, it is recommended to update Lenovo System Update to version 5.07.0084 or later.
More information about CVE-2019-6163 can be found in the Lenovo support article: https://support.lenovo.com/solutions/LEN-27348