Skip to main content

Go to Calendar     Go to Press Room     Go to Newsletters subscription

  • INCIBE
    • Your Help in Cybersecurity
      • FAQ
    • Training
    • Cibercooperantes Program
    • Press Room
    • Corporate information
      • What is INCIBE
          1. Organisation chart
          2. Internal regulations
      • What we do
      • How do we operate
      • Who we work with
          1. European projects participation
          2. Memberships
          3. Network of excellence on cybersecurity R&D&i
          4. Companies
      • Contracting Organisation Profile
      • Calendar
  • INCIBE-CERT
    • Early Warning
      • Security Advisories
      • ICS Advisories
      • Vulnerabilities
          1. CNA
          2. CVE assignment and publication
          3. Coordinated CVEs
          4. Participating CNAs
    • Blog
    • Publications
      • Cybersecurity Highlights
      • Guides
      • Webinars
      • Segmented
    • Incidents
      • Incident responses
    • Services
    • About us
      • What is INCIBE-CERT
      • PGP Public keys
      • TLP
      • Vulnerability disclosure policy
      • RFC 2350
  • CITIZENS
    • We help you
      • Tu Ayuda en Ciberseguridad
      • Reporte de fraude
    • Security tools
    • Temáticas
  • MINORS
    • Educators
    • Families
      • Parental Mediation
      • Cybersecurity
    • Youth
    • Hotline
  • Companies
    • We help you
      • Tu Ayuda en Ciberseguridad
    • TemáTICas
  • EVENTS
    • SID
    • Cybersecurity Summer BootCamp
    • ENISE
    • CyberCamp
  • DIGITAL SPAIN 2026
    • Cybersecurity Entrepreneurship
    • NCC-ES INCIBE
    • Internationalization
      • New Markets
      • Exterior Visibility
      • Foreign Investment
 
Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT
  • INCIBE
    •  
    • Your Help in Cybersecurity
      •  
      • FAQ
    • Training
    • Cibercooperantes Program
    • Press Room
    • Corporate information
      •  
      • What is INCIBE
        •  
          1. Organisation chart
          2. Internal regulations
      • What we do
      • How do we operate
      • Who we work with
        •  
          1. European projects participation
          2. Memberships
          3. Network of excellence on cybersecurity R&D&i
          4. Companies
      • Contracting Organisation Profile
      • Calendar
  • INCIBE-CERT
    •  
    • Early Warning
      •  
      • Security Advisories
      • ICS Advisories
      • Vulnerabilities
        •  
          1. CNA
          2. CVE assignment and publication
          3. Coordinated CVEs
          4. Participating CNAs
    • Blog
    • Publications
      •  
      • Cybersecurity Highlights
      • Guides
      • Webinars
      • Segmented
    • Incidents
      •  
      • Incident responses
    • Services
    • About us
      •  
      • What is INCIBE-CERT
      • PGP Public keys
      • TLP
      • Vulnerability disclosure policy
      • RFC 2350
  • CITIZENS
    •  
    • We help you
      •  
      • Tu Ayuda en Ciberseguridad
      • Reporte de fraude
    • Security tools
    • Temáticas
  • MINORS
    •  
    • Educators
    • Families
      •  
      • Parental Mediation
      • Cybersecurity
    • Youth
    • Hotline
  • Companies
    •  
    • We help you
      •  
      • Tu Ayuda en Ciberseguridad
    • TemáTICas
  • EVENTS
    •  
    • SID
    • Cybersecurity Summer BootCamp
    • ENISE
    • CyberCamp
  • DIGITAL SPAIN 2026
    •  
    • Cybersecurity Entrepreneurship
    • NCC-ES INCIBE
    • Internationalization
      •  
      • New Markets
      • Exterior Visibility
      • Foreign Investment

Go to Calendar     Go to Press Room     Go to Newsletters subscription

Search

  1. Home
  2. INCIBE-CERT
  3. Early warning
  4. Vulnerabilities
  5. CVE-2025-12047

CVE-2025-12047

Severity CVSS v4.0:
MEDIUM
Type:
CWE-295 Improper Certificate Validation
Publication date:
12/11/2025
Last modified:
12/11/2025

Description

A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the same logical network to disclose sensitive user files from the application.

Impact

Vector 4.0
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS v4.0 Severity and Metrics:

Base Score: 6.00 MEDIUM
Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Attack Vector (AV): Adjacent
Attack Complexity (AC): High
Attack Requirements (AT): Present
Privileges Required (PR): None
User Interaction (UI): None
Confidentiality (VC): High
Integrity (VI): None
Availability (VA): None
Confidentiality (SC): None
Integrity (SI): None
Availability (SA): None

Base Score 4.0
6.00
Severity 4.0
MEDIUM
Vector 3.x
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS v3.1 Severity and Metrics:

Base Score: 5.30 MEDIUM
Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector (AV): Adjacent
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): High
Integrity (I): None
Availability (A): None

Base Score 3.x
5.30
Severity 3.x
MEDIUM

References to Advisories, Solutions, and Tools

  • https://iknow.lenovo.com.cn/detail/434327
INCIBE-CERT

Newsletter subscription

Nipo: 094-20-022-9

Follow us:  Link to INCIBE-CERT's Twitter Link to INCIBE-CERT's Linkedin Link to INCIBE-CERT's YouTube account

  • Contact
  • Personal Data Protection Policy
  • Legal notice
  • Configure cookies
  • Cookies policy
  • Site Map
  • Contracting Organisation Profile

Funded by the European Union - Next Generation EU

 

Government of Spain. Ministry for digital transformation and public service. Secretary of state for for Telecommunications and Digital Infrastructures

Recovery, Transformation and Resilience Plan

 

Certificado de Conformidad con el Esquema Nacional de Seguridad (ENS) RD 311/2022
Seguridad de la Información, ISO/IEC 27001
Sistema de Gestión de la Calidad, ISO 9001

Nipo: 094-20-027-6

INCIBE on Twitter INCIBE on Instagram INCIBE on Linkedin INCIBE on Facebook INCIBE on YouTube

×

imagen ampliada

Go top