Insecure File Transfer in SHAREit by Lenovo for Android Devices
CVE-2016-1492
6.1MEDIUM
Summary
Lenovo SHAREit for Android prior to version 3.5.48_ww has a significant security vulnerability allowing unauthorized access through its WiFi hotspot feature. When configured to receive files, the hotspot lacks a password requirement, enabling attackers within the WLAN coverage area to execute remote file transfer exploitation. This breaches the confidentiality of data exchanged, posing risks of unauthorized data access.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved