Description
An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.
Published: 2021-11-12
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

For Legion Phone Pro (L79031), perform an Over-The-Air (OTA) system update to version 12.5.231 (or later). For Legion Phone2 Pro (L70081), perform an Over-The-Air (OTA) system update to version 12.5.632 (or later). To check for available updates wirelessly/over-the-air: # Go to Settings > My Phone > System Update If an update is available, follow the instructions on your phone to download and install it. Once updated, your phone will restart to complete the installation.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-27000 An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.
History

No history.

Subscriptions

Lenovo Legion Phone2 Pro \(l70081\) Legion Phone2 Pro \(l70081\) Firmware Legion Phone Pro \(l79031\) Legion Phone Pro \(l79031\)firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:01:08.293Z

Reserved: 2021-08-18T00:00:00.000Z

Link: CVE-2021-3720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-12T22:15:08.007

Modified: 2024-11-21T06:22:14.840

Link: CVE-2021-3720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses