PT-2017-16090 · Lenovo · Lenovo Service Framework

Publicado

2017-10-17

·

Atualizado

2017-11-08

·

CVE-2017-3759

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lenovo Service Framework (affected versions not specified)
Description The issue concerns the Lenovo Service Framework Android application, which fails to properly validate server responses. This lack of validation exposes the application to man-in-the-middle attacks, potentially leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3759

Produtos afetados

Lenovo Service Framework