ID

VAR-202004-2175


CVE

CVE-2020-8327


TITLE

Lenovo Vantage Vulnerability related to authority management in

Trust: 0.8

sources: JVNDB: JVNDB-2020-004046

DESCRIPTION

A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with elevated privileges. Lenovo Vantage Exists in a privilege management vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Lenovo System Interface Foundation is a set of software used by China Lenovo (Lenovo) to communicate with hardware devices. A code issue vulnerability exists in LenovoBatteryGaugePackage in Lenovo System Interface Foundation. An attacker could exploit this vulnerability to elevate privileges and execute code

Trust: 1.71

sources: NVD: CVE-2020-8327 // JVNDB: JVNDB-2020-004046 // VULHUB: VHN-186452

AFFECTED PRODUCTS

vendor:lenovomodel:vantagescope:ltversion:10.2003.10.0

Trust: 1.0

vendor:lenovomodel:vantagescope:eqversion:10.2003.10.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-004046 // NVD: CVE-2020-8327

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8327
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2020-8327
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-004046
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202004-939
value: HIGH

Trust: 0.6

VULHUB: VHN-186452
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2020-8327
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-004046
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-186452
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-8327
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2020-8327
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-004046
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-186452 // JVNDB: JVNDB-2020-004046 // CNNVD: CNNVD-202004-939 // NVD: CVE-2020-8327 // NVD: CVE-2020-8327

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.9

problemtype:CWE-428

Trust: 1.0

sources: VULHUB: VHN-186452 // JVNDB: JVNDB-2020-004046 // NVD: CVE-2020-8327

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202004-939

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202004-939

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-004046

PATCH

title:LEN-30401url:https://support.lenovo.com/us/en/product_security/LEN-30401

Trust: 0.8

title:Lenovo System Interface Foundation Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=115967

Trust: 0.6

sources: JVNDB: JVNDB-2020-004046 // CNNVD: CNNVD-202004-939

EXTERNAL IDS

db:NVDid:CVE-2020-8327

Trust: 2.5

db:LENOVOid:LEN-30401

Trust: 1.7

db:JVNDBid:JVNDB-2020-004046

Trust: 0.8

db:CNNVDid:CNNVD-202004-939

Trust: 0.7

db:CNVDid:CNVD-2020-27281

Trust: 0.1

db:VULHUBid:VHN-186452

Trust: 0.1

sources: VULHUB: VHN-186452 // JVNDB: JVNDB-2020-004046 // CNNVD: CNNVD-202004-939 // NVD: CVE-2020-8327

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-30401

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-8327

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8327

Trust: 0.8

sources: VULHUB: VHN-186452 // JVNDB: JVNDB-2020-004046 // CNNVD: CNNVD-202004-939 // NVD: CVE-2020-8327

SOURCES

db:VULHUBid:VHN-186452
db:JVNDBid:JVNDB-2020-004046
db:CNNVDid:CNNVD-202004-939
db:NVDid:CVE-2020-8327

LAST UPDATE DATE

2024-11-23T22:05:39.258000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-186452date:2020-04-15T00:00:00
db:JVNDBid:JVNDB-2020-004046date:2020-05-01T00:00:00
db:CNNVDid:CNNVD-202004-939date:2020-04-17T00:00:00
db:NVDid:CVE-2020-8327date:2024-11-21T05:38:43.173

SOURCES RELEASE DATE

db:VULHUBid:VHN-186452date:2020-04-14T00:00:00
db:JVNDBid:JVNDB-2020-004046date:2020-05-01T00:00:00
db:CNNVDid:CNNVD-202004-939date:2020-04-14T00:00:00
db:NVDid:CVE-2020-8327date:2020-04-14T21:15:16.197