CVE-2021-3720
 
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.
Se ha informado de una vulnerabilidad de divulgación de información en el widget del sistema Time Weather en Legion Phone Pro (L79031) y Legion Phone2 Pro (L70081) que podría permitir a otras aplicaciones acceder a los datos del GPS del dispositivo
*Credits:
Lenovo thanks Xiaofeng Liu (Shandong University) and Qinsheng Hou (Shandong University & Qi An Xin Group Corp.) for reporting this issue.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-08-18 CVE Reserved
- 2021-11-12 CVE Published
- 2023-06-05 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://iknow.lenovo.com.cn/detail/dc_199217.html | 2021-11-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lenovo Search vendor "Lenovo" | Legion Phone Pro \(l79031\)firmware Search vendor "Lenovo" for product "Legion Phone Pro \(l79031\)firmware" | < 12.5.231 Search vendor "Lenovo" for product "Legion Phone Pro \(l79031\)firmware" and version " < 12.5.231" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Legion Phone Pro \(l79031\) Search vendor "Lenovo" for product "Legion Phone Pro \(l79031\)" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | Legion Phone2 Pro \(l70081\) Firmware Search vendor "Lenovo" for product "Legion Phone2 Pro \(l70081\) Firmware" | < 12.5.632 Search vendor "Lenovo" for product "Legion Phone2 Pro \(l70081\) Firmware" and version " < 12.5.632" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Legion Phone2 Pro \(l70081\) Search vendor "Lenovo" for product "Legion Phone2 Pro \(l70081\)" | - | - |
Safe
|