PT-2021-21571 · Lenovo · Legion Phone2 Pro+1

Qinsheng Hou

+1

·

Published

2021-11-12

·

Updated

2021-11-16

·

CVE-2021-3720

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Legion Phone Pro version L79031 Legion Phone2 Pro version L70081
Description An information disclosure issue was reported in the Time Weather system widget that could allow other applications to access device GPS data.
Recommendations For Legion Phone Pro version L79031, consider restricting access to the Time Weather system widget until a fix is available. For Legion Phone2 Pro version L70081, consider restricting access to the Time Weather system widget until a fix is available. As a temporary workaround, consider disabling the Time Weather system widget to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3720

Affected Products

Legion Phone Pro
Legion Phone2 Pro