CVE-2015-7336
Last modified
CVE-2015-7336 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | System Update | <= 5.07.0008 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7336?
How severe is CVE-2015-7336?
How do I fix CVE-2015-7336?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7328Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3…
- CVE-2015-7330Puppet Enterprise 2015.3 before 2015.3.1 allows remote attac…
- CVE-2015-7331The mcollective-puppet-agent plugin before 1.11.1 for Puppet…
- CVE-2015-7333MITRE is populating this ID because it was assigned prior to…7.8
- CVE-2015-7334MITRE is populating this ID because it was assigned prior to…7.8
- CVE-2015-7335MITRE is populating this ID because it was assigned prior to…7
- CVE-2015-7337The editor in IPython Notebook before 3.2.2 and Jupyter Note…
- CVE-2015-7338SQL Injection exists in AcyMailing Joomla Component before 4…7.2
- CVE-2015-7339JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file up…8.8
- CVE-2015-7340JEvents Joomla Component before 3.4.0 RC6 has SQL Injection …7.2
- CVE-2015-7341JNews Joomla Component before 8.5.0 allows arbitrary File Up…8.8
- CVE-2015-7342JNews Joomla Component before 8.5.0 allows SQL injection via…7.2
Are you affected by CVE-2015-7336?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
