CVE-2017-3743
Summary
| CVE | CVE-2017-3743 |
|---|---|
| State | PUBLISHED |
| Assigner | lenovo |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-20 00:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-200 | Sensitive information disclosure
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lenovo | Advanced Settings Utility | All | All | All | All |
| Application | Lenovo | Toolscenter Dynamic System Analysis | All | All | All | All |
| Application | Lenovo | Updatexpress System Pack Installer | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lenovo Group Ltd. | ToolsCenter | affected Lenovo Advanced Settings Utility versions earlier than 10.2 and UXSPI and DSA versions earlier than 10.3 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Credentials sent through the Lenovo ToolsCenter may be exposed to local users - Lenovo Support US | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.