7.8

CVE-2017-3748

On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version <= 5.1.1
   LenovoVibe A1600 Version-
   LenovoVibe A2560 Version-
   LenovoVibe A2800 Version-
   LenovoVibe A2860 Version-
   LenovoVibe A2880 Version-
   LenovoVibe A3000 Version-
   LenovoVibe A3500 Version-
   LenovoVibe A3600-d Version-
   LenovoVibe A3600u Version-
   LenovoVibe A3800-d Version-
   LenovoVibe A3900 Version-
   LenovoVibe A6000 Version-
   LenovoVibe A6000-i Version-
   LenovoVibe A6020i37 Version-
   LenovoVibe A6600 Version-
   LenovoVibe A6800 Version-
   LenovoVibe K30-e Version-
   LenovoVibe K30-w-cu Version-
   LenovoVibe K32c30 Version-
   LenovoVibe K80m Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.