ID

VAR-202007-1424


CVE

CVE-2020-8326


TITLE

Lenovo Drivers Management Vulnerabilities in unquoted search paths or elements in

Trust: 0.8

sources: JVNDB: JVNDB-2020-008820

DESCRIPTION

An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges. (DoS) It may be put into a state. Lenovo Drivers Management is a driver management application for Lenovo products from China Lenovo (Lenovo). This program is mainly used for driver installation and upgrade, etc

Trust: 1.71

sources: NVD: CVE-2020-8326 // JVNDB: JVNDB-2020-008820 // VULHUB: VHN-186451

AFFECTED PRODUCTS

vendor:lenovomodel:drivers managementscope:ltversion:2.7.1128.1046

Trust: 1.0

vendor:lenovomodel:drivers managementscope:eqversion:2.7.1128.1046

Trust: 0.8

sources: JVNDB: JVNDB-2020-008820 // NVD: CVE-2020-8326

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8326
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2020-8326
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-008820
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202007-1522
value: HIGH

Trust: 0.6

VULHUB: VHN-186451
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-8326
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-008820
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-186451
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-8326
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@lenovo.com: CVE-2020-8326
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-008820
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-186451 // JVNDB: JVNDB-2020-008820 // CNNVD: CNNVD-202007-1522 // NVD: CVE-2020-8326 // NVD: CVE-2020-8326

PROBLEMTYPE DATA

problemtype:CWE-428

Trust: 1.9

sources: VULHUB: VHN-186451 // JVNDB: JVNDB-2020-008820 // NVD: CVE-2020-8326

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202007-1522

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202007-1522

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-008820

PATCH

title:LEN-38381url:https://iknow.lenovo.com.cn/detail/dc_190088.html

Trust: 0.8

title:Lenovo Drivers Management Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=124838

Trust: 0.6

sources: JVNDB: JVNDB-2020-008820 // CNNVD: CNNVD-202007-1522

EXTERNAL IDS

db:NVDid:CVE-2020-8326

Trust: 2.5

db:JVNDBid:JVNDB-2020-008820

Trust: 0.8

db:CNNVDid:CNNVD-202007-1522

Trust: 0.7

db:NSFOCUSid:47895

Trust: 0.6

db:CNVDid:CNVD-2020-44072

Trust: 0.1

db:VULHUBid:VHN-186451

Trust: 0.1

sources: VULHUB: VHN-186451 // JVNDB: JVNDB-2020-008820 // CNNVD: CNNVD-202007-1522 // NVD: CVE-2020-8326

REFERENCES

url:https://iknow.lenovo.com.cn/detail/dc_190088.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-8326

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8326

Trust: 0.8

url:http://www.nsfocus.net/vulndb/47895

Trust: 0.6

sources: VULHUB: VHN-186451 // JVNDB: JVNDB-2020-008820 // CNNVD: CNNVD-202007-1522 // NVD: CVE-2020-8326

SOURCES

db:VULHUBid:VHN-186451
db:JVNDBid:JVNDB-2020-008820
db:CNNVDid:CNNVD-202007-1522
db:NVDid:CVE-2020-8326

LAST UPDATE DATE

2024-11-23T21:51:24.495000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-186451date:2020-07-29T00:00:00
db:JVNDBid:JVNDB-2020-008820date:2020-09-28T00:00:00
db:CNNVDid:CNNVD-202007-1522date:2020-08-19T00:00:00
db:NVDid:CVE-2020-8326date:2024-11-21T05:38:43.063

SOURCES RELEASE DATE

db:VULHUBid:VHN-186451date:2020-07-24T00:00:00
db:JVNDBid:JVNDB-2020-008820date:2020-09-28T00:00:00
db:CNNVDid:CNNVD-202007-1522date:2020-07-24T00:00:00
db:NVDid:CVE-2020-8326date:2020-07-24T16:15:12.193