Vulnerability Description
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Lenovo Service Bridge | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-10149Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-10149Vendor Advisory
FAQ
What is CVE-2016-8230?
CVE-2016-8230 is a vulnerability with a CVSS score of 7.5 (HIGH). In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
How severe is CVE-2016-8230?
CVE-2016-8230 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8230?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Lenovo Service Bridge.