Improper Access Controls in Lenovo VIBE Mobile Phones
CVE-2017-3748
7.8HIGH
Key Information:
- Vendor
- Lenovo
- Vendor
- CVE Published:
- 22 June 2017
Summary
On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be exploited to gain elevated privileges, potentially allowing attackers to achieve root access. This vulnerability can be combined with other vulnerabilities to facilitate unauthorized modifications to the device's operating system, often referred to as 'rooting' or 'jailbreaking'. Users and administrators are advised to review security patches and updates to safeguard against this vulnerability.
Affected Version(s)
Lenovo Vibe and Lenovo China-only Moto Mobile Phones Earlier than 6.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved