PT-2021-7012 · Lenovo · Lenovo Pcmanager
She Zhenhua
·
Published
2021-08-18
·
Updated
2022-05-06
·
CVE-2021-3722
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Lenovo PCManager versions prior to 4.0.40.2175
Description
A denial of service issue was reported that could allow configuration files to be written to non-standard locations during installation. The vulnerability is related to insufficient access control, which could enable an attacker to cause a denial of service.
Recommendations
For versions prior to 4.0.40.2175, update to version 4.0.40.2175 or later to resolve the issue. As a temporary workaround, consider restricting access to configuration files during installation to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lenovo Pcmanager