3.3
CVE-2023-5081
- EPSS 0.09%
- Veröffentlicht 19.01.2024 20:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:01
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Tab M8 Hd Tb8505f Firmware Version < 8505f_usr_s301106_2309140042_v9.56_bmp_row
Lenovo ≫ Tab M8 Hd Tb8505fs Firmware Version < 8505fs_usr_s301107_2309140028_v9.56_bmp_row
Lenovo ≫ Tab M8 Hd Tb8505x Firmware Version < 8505x_usr_s301129_2309141226_v9.56_bmp_row
Lenovo ≫ Tab M8 Hd Tb8505xs Firmware Version < 8505xs_usr_s301077_2309140036_v9.56_bmp_row
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.27 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
psirt@lenovo.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.