Vulnerability Description
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Dynamic Power Reduction | < 2.2.2.0 |
| Lenovo | Thinkpad X1 Carbon | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107438
- https://support.lenovo.com/solutions/LEN-25674Vendor Advisory
- http://www.securityfocus.com/bid/107438
- https://support.lenovo.com/solutions/LEN-25674Vendor Advisory
FAQ
What is CVE-2019-6149?
CVE-2019-6149 is a vulnerability with a CVSS score of 6.7 (MEDIUM). An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with adminis...
How severe is CVE-2019-6149?
CVE-2019-6149 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6149?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Dynamic Power Reduction, Lenovo Thinkpad X1 Carbon.