CVE-2018-9070
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.
Para la aplicación de Android Lenovo Smart Assistant en versiones anteriores a la 12.1.82, un atacante con acceso físico al altavoz inteligente puede, pulsando una determinada secuencia de botones, entrar en el modo de pruebas de fábrica y habilitar un servicio web destinado a probar el dispositivo. Como con la mayoría de modos de prueba, éste proporciona privilegios extras, incluyendo el cambio de configuración y la ejecución de código. Lenovo Smart Assistant es un altavoz inteligente diseñado para Amazon Alexa desarrollado por Lenovo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-27 CVE Reserved
- 2018-07-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.lenovo.com/us/en/solutions/LEN-22172 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lenovo Search vendor "Lenovo" | Smart Assistant Search vendor "Lenovo" for product "Smart Assistant" | < 12.1.82 Search vendor "Lenovo" for product "Smart Assistant" and version " < 12.1.82" | android |
Affected
|