NVD

Id
24340  
Name
CVE-2015-2233  
Description
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.  
Reject
 
CVSS Version
2  
CVSS Score
8.3  
Severity
High  
CVSS Base Score
8.3  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:C/I:C/A:C)  
Pub Date
2017-01-19  
Published
2015-05-12  
Modified Date
2016-12-02  
Seq
2015-2233  

Actions