CVE-2025-6026
Severity CVSS v4.0:
LOW
Type:
CWE-295
Improper Certificate Validation
Publication date:
15/10/2025
Last modified:
16/10/2025
Description
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
3.10
Severity 3.x
LOW