CVE-2015-7336

HIGH

Lenovo System Update < 5.07.0008 - Cryptographic Signature Bypass

Title source: llm
STIX 2.1

Description

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-347
Status published
Products (1)
lenovo/system_update < 5.07.0008
Published Mar 27, 2020
Tracked Since Feb 18, 2026