CVE-2024-6001

An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.

Credits

Lenovo thanks jh_535252 for reporting this issue.

References