Privilege Escalation Vulnerability in Lenovo VIBE Mobile Phones
CVE-2017-3750
6.4MEDIUM
Key Information:
- Vendor
- Lenovo
- Vendor
- CVE Published:
- 29 June 2017
Summary
The Lenovo VIBE mobile phones contain a vulnerability in the Lenovo Security Android application where private data can be backed up and restored using the Android Debug Bridge (ADB). This flaw allows malicious actors to manipulate the device and escalate privileges, particularly when exploited in conjunction with other identified vulnerabilities. Users are encouraged to update their devices and follow security best practices to mitigate risks associated with this issue.
Affected Version(s)
Lenovo Vibe and Lenovo China-only Moto Mobile Phones Earlier than 6.0
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved