Vulnerability Description
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | System Update | <= 5.07.0008 |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/lsu_privilegeVendor Advisory
- https://support.lenovo.com/us/en/product_security/lsu_privilegeVendor Advisory
FAQ
What is CVE-2015-7336?
CVE-2015-7336 is a vulnerability with a CVSS score of 7.5 (HIGH). MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and pr...
How severe is CVE-2015-7336?
CVE-2015-7336 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7336?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo System Update.