CVE-2017-3750
Summary
| CVE | CVE-2017-3750 |
|---|---|
| State | PUBLISHED |
| Assigner | lenovo |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-29 15:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749. |
Risk And Classification
Primary CVSS: v3.0 6.4 MEDIUM from [email protected]
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: NVD-CWE-noinfo | Privilege escalation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.4 | MEDIUM | CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.9 | AV:L/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
PhysicalAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Android | All | All | All | All | |
| Hardware | Lenovo | Vibe A1600 | - | All | All | All |
| Hardware | Lenovo | Vibe A2560 | - | All | All | All |
| Hardware | Lenovo | Vibe A2800 | - | All | All | All |
| Hardware | Lenovo | Vibe A2860 | - | All | All | All |
| Hardware | Lenovo | Vibe A2880 | - | All | All | All |
| Hardware | Lenovo | Vibe A3000 | - | All | All | All |
| Hardware | Lenovo | Vibe A3500 | - | All | All | All |
| Hardware | Lenovo | Vibe A3600-d | - | All | All | All |
| Hardware | Lenovo | Vibe A3600u | - | All | All | All |
| Hardware | Lenovo | Vibe A3800-d | - | All | All | All |
| Hardware | Lenovo | Vibe A3900 | - | All | All | All |
| Hardware | Lenovo | Vibe A6000 | - | All | All | All |
| Hardware | Lenovo | Vibe A6000-i | - | All | All | All |
| Hardware | Lenovo | Vibe A6020i37 | - | All | All | All |
| Hardware | Lenovo | Vibe A6600 | - | All | All | All |
| Hardware | Lenovo | Vibe A6800 | - | All | All | All |
| Hardware | Lenovo | Vibe K30-e | - | All | All | All |
| Hardware | Lenovo | Vibe K30-w-cu | - | All | All | All |
| Hardware | Lenovo | Vibe K32c30 | - | All | All | All |
| Hardware | Lenovo | Vibe K80m | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lenovo Group Ltd. | Lenovo Vibe And Lenovo China-only Moto Mobile Phones | affected Earlier than 6.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Local Root Exploit on Lenovo VIBE Mobile Phones | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.