CVE-2025-6230: SQL Injection
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lenovo Commercial Vantageto a version that resolves this vulnerability.Fixed in 20.2506.39.0 - Upgrade
Upgrade
Lenovo Vantageto a version that resolves this vulnerability.Fixed in 10.2501.20.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6230?
CVE-2025-6230 is classified as a high-severity vulnerability due to its potential to allow local code execution with elevated permissions.
How do I fix CVE-2025-6230?
To fix CVE-2025-6230, update Lenovo Vantage to the latest version provided by Lenovo that addresses this vulnerability.
Who is affected by CVE-2025-6230?
CVE-2025-6230 affects users of Lenovo Vantage, particularly those running vulnerable versions of the application.
Can CVE-2025-6230 be exploited remotely?
CVE-2025-6230 cannot be exploited remotely since it requires local access to the system.
What are the risks associated with CVE-2025-6230?
The risks of CVE-2025-6230 include unauthorized modifications to the SQLite database and potential execution of malicious code with elevated privileges.