{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-10495","assignerOrgId":"da227ddf-6e25-4b41-b023-0f976dcaca4b","state":"PUBLISHED","assignerShortName":"lenovo","dateReserved":"2025-09-15T19:25:35.895Z","datePublished":"2025-11-12T19:18:44.859Z","dateUpdated":"2026-02-26T16:57:09.944Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"App Store","vendor":"Lenovo","versions":[{"lessThan":"9.0.2530.1027","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"PC Manager","vendor":"Lenovo","versions":[{"lessThan":"5.1.140.9262","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"Browser","vendor":"Lenovo","versions":[{"lessThan":"9.0.6.9111","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"Legion Zone","vendor":"Lenovo","versions":[{"lessThan":"2.0.21","status":"affected","version":"0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:lenovo:app_store:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0.2530.1027","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:lenovo:pc_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"5.1.140.9262","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:lenovo:browser:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0.6.9111","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:lenovo:legion_zone:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0.21","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.  <br>"}],"value":"A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":7.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"CWE-295: Improper Certificate Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"da227ddf-6e25-4b41-b023-0f976dcaca4b","shortName":"lenovo","dateUpdated":"2025-11-12T19:18:44.859Z"},"references":[{"url":"https://iknow.lenovo.com.cn/detail/434328"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update Lenovo App Store Client to version 9.0.2530.1027 or later.<br>"}],"value":"Update Lenovo App Store Client to version 9.0.2530.1027 or later."},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update Lenovo PC Manager to version 5.1.140.9262 or later.<br>"}],"value":"Update Lenovo PC Manager to version 5.1.140.9262 or later."},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update Lenovo Browser Client to version 9.0.6.9111 or later.<br>"}],"value":"Update Lenovo Browser Client to version 9.0.6.9111 or later."},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update Legion Zone Client to version 2.0.21 or later.<br>"}],"value":"Update Legion Zone Client to version 2.0.21 or later."}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.3.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-10495","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-11-13T04:55:37.393427Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T16:57:09.944Z"}}]}}