CVE-2025-12047

MEDIUM

Lenovo Scanner pro - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the same logical network to disclose sensitive user files from the application.

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 6.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
Lenovo/Scanner Pro < 1.2.7
Published Nov 12, 2025
Tracked Since Feb 18, 2026