3.3
CWE
497
Advisory Published
Updated

CVE-2023-5081

First published: Fri Jan 19 2024(Updated: )

An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.

Credit: psirt@lenovo.com

Affected SoftwareAffected VersionHow to fix
All of
Lenovo Tab M8 Hd Tb8505f Firmware<8505f_usr_s301106_2309140042_v9.56_bmp_row
Lenovo Tab M8 Hd Tb8505f
All of
Lenovo Tab M8 Hd Tb8505fs Firmware<8505fs_usr_s301107_2309140028_v9.56_bmp_row
Lenovo Tab M8 Hd Tb8505fs
All of
Lenovo Tab M8 Hd Tb8505x Firmware<8505x_usr_s301129_2309141226_v9.56_bmp_row
Lenovo Tab M8 Hd Tb8505x
All of
Lenovo Tab M8 Hd Tb8505xs Firmware<8505xs_usr_s301077_2309140036_v9.56_bmp_row
Lenovo Tab M8 Hd Tb8505xs

Remedy

Update to the version (or newer) indicated for your model in the Product Impact section in the advisory: https://support.lenovo.com/us/en/product_security/LEN-142135

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2023-5081?

    CVE-2023-5081 is classified as an information disclosure vulnerability.

  • How do I fix CVE-2023-5081?

    To fix CVE-2023-5081, update your Lenovo Tab M8 HD firmware to the latest version provided by Lenovo.

  • What devices are affected by CVE-2023-5081?

    CVE-2023-5081 affects multiple models of the Lenovo Tab M8 HD, including TB8505F, TB8505FS, TB8505X, and TB8505XS firmware versions.

  • What type of information is disclosed in CVE-2023-5081?

    CVE-2023-5081 can allow a local application to gather a non-resettable device identifier.

  • Is CVE-2023-5081 exploitable remotely?

    CVE-2023-5081 requires local access, so it is not exploitable remotely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203