CVE-2019-6166: CSRF
Published Jun 26, 2019
·Updated
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
Affected Software
8 affected components
Lenovo Service Bridge<4.1.0.1
Lenovo Ideacentre
Lenovo Ideapad
Lenovo Tablet Windows
Lenovo Thinkcentre
Lenovo ThinkPad
Lenovo Thinkstation
Lenovo Yoga
Remediation
Information
Upgrade to Lenovo Service Bridge version 4.1.0.1 (or newer).
Event History
Jun 26, 2019
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Lenovo Service Bridge vulnerability?
The vulnerability ID for this Lenovo Service Bridge vulnerability is CVE-2019-6166.
2
What is the severity level of CVE-2019-6166?
CVE-2019-6166 has a severity level of 8.8, which is considered high.
3
What is the affected software for CVE-2019-6166?
The affected software is Lenovo Service Bridge before version 4.1.0.1.
4
What is the CWE ID for CVE-2019-6166?
The CWE ID for CVE-2019-6166 is 352.
5
How can I fix this vulnerability?
To fix this vulnerability, update Lenovo Service Bridge to version 4.1.0.1 or later.