PT-2018-18831 · Lenovo · Lenovo Smart Assistant

Published

2018-07-13

·

Updated

2019-10-03

·

CVE-2018-9070

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo Smart Assistant Android app versions prior to 12.1.82
Description An issue exists where an attacker with physical access to the smart speaker can enter factory test mode by pressing a specific button sequence. This mode provides extra privileges, including changing settings and running code.
Recommendations For versions prior to 12.1.82, update to version 12.1.82 or later to resolve the issue. As a temporary workaround, consider restricting physical access to the smart speaker to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-9070

Affected Products

Lenovo Smart Assistant