An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.
Weakness
The product is released with debugging code still enabled or active.
Potential Mitigations
References