Impact
The vulnerability in the Lenovo Health Android Application permits an attacker to read sensitive health flaw arises from the use of hard‑coded credentials, identified as CWE‑798, allowing the retrieval of personal health data and raising significant privacy concerns.
Affected Systems
Lenovo Health Android Application, distributed only in the Chinese market. Versions prior to 1.5.0 are vulnerable; the vendor recommends upgrading to 1.5.0 or later.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity risk of data exposure. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, suggesting no widespread exploitation has been reported yet. Attack access is not explicitly disclosed in the advisory; it is inferred that an attacker could exploit the installed application itself, potentially through local use or via a remote trigger. Consequently, the likelihood of exploitation depends on device.
OpenCVE Enrichment