6.9
CVE-2017-3749
- EPSS 0.01%
- Veröffentlicht 29.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@lenovo.com
- CVE-Watchlists
- Unerledigt
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version <= 5.1.1
Lenovo ≫ Vibe A1600 Version-
Lenovo ≫ Vibe A2560 Version-
Lenovo ≫ Vibe A2800 Version-
Lenovo ≫ Vibe A2860 Version-
Lenovo ≫ Vibe A2880 Version-
Lenovo ≫ Vibe A3000 Version-
Lenovo ≫ Vibe A3500 Version-
Lenovo ≫ Vibe A3600-d Version-
Lenovo ≫ Vibe A3600u Version-
Lenovo ≫ Vibe A3800-d Version-
Lenovo ≫ Vibe A3900 Version-
Lenovo ≫ Vibe A6000 Version-
Lenovo ≫ Vibe A6000-i Version-
Lenovo ≫ Vibe A6020i37 Version-
Lenovo ≫ Vibe A6600 Version-
Lenovo ≫ Vibe A6800 Version-
Lenovo ≫ Vibe K30-e Version-
Lenovo ≫ Vibe K30-w-cu Version-
Lenovo ≫ Vibe K32c30 Version-
Lenovo ≫ Vibe K80m Version-
Lenovo ≫ Vibe A2560 Version-
Lenovo ≫ Vibe A2800 Version-
Lenovo ≫ Vibe A2860 Version-
Lenovo ≫ Vibe A2880 Version-
Lenovo ≫ Vibe A3000 Version-
Lenovo ≫ Vibe A3500 Version-
Lenovo ≫ Vibe A3600-d Version-
Lenovo ≫ Vibe A3600u Version-
Lenovo ≫ Vibe A3800-d Version-
Lenovo ≫ Vibe A3900 Version-
Lenovo ≫ Vibe A6000 Version-
Lenovo ≫ Vibe A6000-i Version-
Lenovo ≫ Vibe A6020i37 Version-
Lenovo ≫ Vibe A6600 Version-
Lenovo ≫ Vibe A6800 Version-
Lenovo ≫ Vibe K30-e Version-
Lenovo ≫ Vibe K30-w-cu Version-
Lenovo ≫ Vibe K32c30 Version-
Lenovo ≫ Vibe K80m Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 0.5 | 5.9 |
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|