An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-198727 |
|
History
Tue, 21 Oct 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data. | An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data. |
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lenovo
Lenovo universal Device Client |
|
| Vendors & Products |
Lenovo
Lenovo universal Device Client |
Thu, 16 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published: 2025-10-15T14:25:29.294Z
Updated: 2025-10-21T12:22:42.749Z
Reserved: 2025-06-12T12:28:13.697Z
Link: CVE-2025-6026
Updated: 2025-10-15T16:04:10.371Z
Status : Awaiting Analysis
Published: 2025-10-15T15:16:06.710
Modified: 2025-10-21T13:15:36.800
Link: CVE-2025-6026
No data.