CVE-2019-6163: High severity Lenovo System Update vulnerability
Published Jun 26, 2019
·Updated
A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations.
Affected Software
24 affected components
Lenovo System Update<5.07.0084
Lenovo B Series
Lenovo C100
Lenovo C200
Lenovo E Series
Lenovo J100
Lenovo J105
Lenovo J110
Lenovo J115
Lenovo J200
Lenovo J200p
Lenovo J205
Lenovo K Series
Lenovo N100
Lenovo N200
Lenovo S200
Lenovo S200p
Lenovo S205
Lenovo Thinkcentre
Lenovo ThinkPad
Lenovo Thinkstation
Lenovo V Series
Lenovo V100
Lenovo V200
Remediation
Information
Upgrade to the Lenovo System Update version 5.07.0084 (or newer).
Event History
Jun 26, 2019
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-6163?
CVE-2019-6163 is a denial of service vulnerability in Lenovo System Update before version 5.07.0084.
2
What is the severity of CVE-2019-6163?
The severity of CVE-2019-6163 is high, with a CVSS score of 7.5.
3
How does CVE-2019-6163 affect Lenovo System Update?
CVE-2019-6163 could allow service log files to be written to non-standard locations in Lenovo System Update before version 5.07.0084.
4
How can I fix CVE-2019-6163?
To fix CVE-2019-6163, it is recommended to update Lenovo System Update to version 5.07.0084 or later.
5
Where can I find more information about CVE-2019-6163?
More information about CVE-2019-6163 can be found in the Lenovo support article: https://support.lenovo.com/solutions/LEN-27348