Improper Access Controls in Lenovo VIBE Mobile Phones
CVE-2017-3748

7.8HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
22 June 2017

Summary

On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be exploited to gain elevated privileges, potentially allowing attackers to achieve root access. This vulnerability can be combined with other vulnerabilities to facilitate unauthorized modifications to the device's operating system, often referred to as 'rooting' or 'jailbreaking'. Users and administrators are advised to review security patches and updates to safeguard against this vulnerability.

Affected Version(s)

Lenovo Vibe and Lenovo China-only Moto Mobile Phones Earlier than 6.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.