// For flags

CVE-2018-9070

 

Severity Score

6.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.

Para la aplicación de Android Lenovo Smart Assistant en versiones anteriores a la 12.1.82, un atacante con acceso físico al altavoz inteligente puede, pulsando una determinada secuencia de botones, entrar en el modo de pruebas de fábrica y habilitar un servicio web destinado a probar el dispositivo. Como con la mayoría de modos de prueba, éste proporciona privilegios extras, incluyendo el cambio de configuración y la ejecución de código. Lenovo Smart Assistant es un altavoz inteligente diseñado para Amazon Alexa desarrollado por Lenovo.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-27 CVE Reserved
  • 2018-07-13 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lenovo
Search vendor "Lenovo"
Smart Assistant
Search vendor "Lenovo" for product "Smart Assistant"
< 12.1.82
Search vendor "Lenovo" for product "Smart Assistant" and version " < 12.1.82"
android
Affected