On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Google
Subscribe
|
Android
Subscribe
|
|
Lenovo
Subscribe
|
Vibe A1600
Subscribe
Vibe A2560
Subscribe
Vibe A2800
Subscribe
Vibe A2860
Subscribe
Vibe A2880
Subscribe
Vibe A3000
Subscribe
Vibe A3500
Subscribe
Vibe A3600-d
Subscribe
Vibe A3600u
Subscribe
Vibe A3800-d
Subscribe
Vibe A3900
Subscribe
Vibe A6000
Subscribe
Vibe A6000-i
Subscribe
Vibe A6020i37
Subscribe
Vibe A6600
Subscribe
Vibe A6800
Subscribe
Vibe K30-e
Subscribe
Vibe K30-w-cu
Subscribe
Vibe K32c30
Subscribe
Vibe K80m
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-12867 | On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-15823 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T22:40:14.066Z
Reserved: 2016-12-16T00:00:00
Link: CVE-2017-3750
No data.
Status : Deferred
Published: 2017-06-29T15:29:00.253
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-3750
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD