7.7
/ 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote code execution or unauthorized control of the affected system.
Basic Information
ID
CVE-2025-12048
Source
lenovo
Published
Nov 12, 2025 at 19:19
Modified
Nov 12, 2025 at 21:03
Affected Product
Vendor
Lenovo
Product
Scanner Pro
Affected Versions
Lenovo Scanner Pro 0