ID

VAR-202007-1184


CVE

CVE-2020-8317


TITLE

Lenovo Drivers Management Unreliable search path vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-008819

DESCRIPTION

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges. Lenovo Drivers Management Exists in an unreliable search path vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Lenovo Drivers Management is a driver management application for Lenovo products from China Lenovo (Lenovo). This program is mainly used for driver installation and upgrade, etc

Trust: 1.71

sources: NVD: CVE-2020-8317 // JVNDB: JVNDB-2020-008819 // VULHUB: VHN-186442

AFFECTED PRODUCTS

vendor:lenovomodel:drivers managementscope:ltversion:2.7.1128.1046

Trust: 1.0

vendor:lenovomodel:drivers managementscope:eqversion:2.7.1128.1046

Trust: 0.8

sources: JVNDB: JVNDB-2020-008819 // NVD: CVE-2020-8317

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8317
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2020-8317
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-008819
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202007-1521
value: HIGH

Trust: 0.6

VULHUB: VHN-186442
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-8317
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-008819
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-186442
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-8317
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2020-8317
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-008819
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-186442 // JVNDB: JVNDB-2020-008819 // CNNVD: CNNVD-202007-1521 // NVD: CVE-2020-8317 // NVD: CVE-2020-8317

PROBLEMTYPE DATA

problemtype:CWE-426

Trust: 1.9

sources: VULHUB: VHN-186442 // JVNDB: JVNDB-2020-008819 // NVD: CVE-2020-8317

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202007-1521

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202007-1521

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-008819

PATCH

title:LEN-38381url:https://iknow.lenovo.com.cn/detail/dc_190088.html

Trust: 0.8

title:Lenovo Drivers Management Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=124837

Trust: 0.6

sources: JVNDB: JVNDB-2020-008819 // CNNVD: CNNVD-202007-1521

EXTERNAL IDS

db:NVDid:CVE-2020-8317

Trust: 2.5

db:JVNDBid:JVNDB-2020-008819

Trust: 0.8

db:CNNVDid:CNNVD-202007-1521

Trust: 0.7

db:NSFOCUSid:47910

Trust: 0.6

db:CNVDid:CNVD-2020-44071

Trust: 0.1

db:VULHUBid:VHN-186442

Trust: 0.1

sources: VULHUB: VHN-186442 // JVNDB: JVNDB-2020-008819 // CNNVD: CNNVD-202007-1521 // NVD: CVE-2020-8317

REFERENCES

url:https://iknow.lenovo.com.cn/detail/dc_190088.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-8317

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8317

Trust: 0.8

url:http://www.nsfocus.net/vulndb/47910

Trust: 0.6

sources: VULHUB: VHN-186442 // JVNDB: JVNDB-2020-008819 // CNNVD: CNNVD-202007-1521 // NVD: CVE-2020-8317

SOURCES

db:VULHUBid:VHN-186442
db:JVNDBid:JVNDB-2020-008819
db:CNNVDid:CNNVD-202007-1521
db:NVDid:CVE-2020-8317

LAST UPDATE DATE

2024-11-23T22:21:04.737000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-186442date:2020-07-29T00:00:00
db:JVNDBid:JVNDB-2020-008819date:2020-09-28T00:00:00
db:CNNVDid:CNNVD-202007-1521date:2020-08-20T00:00:00
db:NVDid:CVE-2020-8317date:2024-11-21T05:38:41.690

SOURCES RELEASE DATE

db:VULHUBid:VHN-186442date:2020-07-24T00:00:00
db:JVNDBid:JVNDB-2020-008819date:2020-09-28T00:00:00
db:CNNVDid:CNNVD-202007-1521date:2020-07-24T00:00:00
db:NVDid:CVE-2020-8317date:2020-07-24T16:15:12.053