CVE-2021-3720
Summary
| CVE | CVE-2021-3720 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-12 22:15:00 UTC |
| Updated | 2021-11-16 20:30:00 UTC |
| Description | An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Legion Phone2 Pro L70081 | - | All | All | All |
| Operating System | Lenovo | Legion Phone2 Pro L70081 Firmware | All | All | All | All |
| Hardware | Lenovo | Legion Phone Pro L79031 | - | All | All | All |
| Operating System | Lenovo | Legion Phone Pro L79031firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 联想中国(Lenovo China)联想知识库 | CONFIRM | iknow.lenovo.com.cn | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Lenovo thanks Xiaofeng Liu (Shandong University) and Qinsheng Hou (Shandong University & Qi An Xin Group Corp.) for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.