CVE-2015-8109

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenovo:lenovo_system_update:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:38

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/98039 - () http://www.securityfocus.com/bid/98039 -
References () https://ioactive.com/pdfs/IOActive_Advisory_Lenovo_SystemUpdate-Insecure-Random-Admin-Password.pdf - Exploit, Third Party Advisory () https://ioactive.com/pdfs/IOActive_Advisory_Lenovo_SystemUpdate-Insecure-Random-Admin-Password.pdf - Exploit, Third Party Advisory
References () https://support.lenovo.com/us/en/product_security/lsu_privilege - Vendor Advisory () https://support.lenovo.com/us/en/product_security/lsu_privilege - Vendor Advisory

Information

Published : 2017-04-24 06:59

Updated : 2024-11-21 02:38


NVD link : CVE-2015-8109

Mitre link : CVE-2015-8109

CVE.ORG link : CVE-2015-8109


JSON object : View

Products Affected

lenovo

  • lenovo_system_update
CWE
CWE-255

Credentials Management Errors