An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update Lenovo UDC to version 25.7.0.21 (or newer). Lenovo UDC is updated automatically through Windows Update.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-198727 |
![]() ![]() |
History
Wed, 15 Oct 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data. | |
Weaknesses | CWE-295 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-10-15T14:25:29.294Z
Reserved: 2025-06-12T12:28:13.697Z
Link: CVE-2025-6026

No data.

Status : Received
Published: 2025-10-15T15:16:06.710
Modified: 2025-10-15T15:16:06.710
Link: CVE-2025-6026

No data.

No data.