PT-2021-21571 · Lenovo · Legion Phone2 Pro+1
Qinsheng Hou
+1
·
Published
2021-11-12
·
Updated
2021-11-16
·
CVE-2021-3720
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Legion Phone Pro version L79031
Legion Phone2 Pro version L70081
Description
An information disclosure issue was reported in the Time Weather system widget that could allow other applications to access device GPS data.
Recommendations
For Legion Phone Pro version L79031, consider restricting access to the Time Weather system widget until a fix is available.
For Legion Phone2 Pro version L70081, consider restricting access to the Time Weather system widget until a fix is available.
As a temporary workaround, consider disabling the Time Weather system widget to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Legion Phone Pro
Legion Phone2 Pro