First published: Wed Jun 26 2019(Updated: )
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Service Bridge | <4.1.0.1 | |
Lenovo Ideacentre | ||
Lenovo Ideapad | ||
Lenovo Tablet | ||
Lenovo Thinkcentre | ||
Lenovo ThinkPad | ||
Lenovo Thinkstation | ||
Lenovo Yoga |
Upgrade to Lenovo Service Bridge version 4.1.0.1 (or newer).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6169 is a vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 that could allow unencrypted downloads over FTP.
Lenovo Service Bridge versions up to and excluding 4.1.0.1 are affected by CVE-2019-6169.
CVE-2019-6169 has a severity rating of 7.5, which is considered high.
To fix CVE-2019-6169, update Lenovo Service Bridge to version 4.1.0.1 or later.
More information about CVE-2019-6169 can be found at the following link: [https://support.lenovo.com/solutions/LEN-27725](https://support.lenovo.com/solutions/LEN-27725).