{"api_version":"1","generated_at":"2026-07-23T09:54:43+00:00","cve":"CVE-2018-9067","urls":{"html":"https://cve.report/CVE-2018-9067","api":"https://cve.report/api/cve/CVE-2018-9067.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-9067","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-9067"},"summary":{"title":"CVE-2018-9067","description":"The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.","state":"PUBLIC","assigner":"psirt@lenovo.com","published_at":"2018-07-13 16:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://support.lenovo.com/us/en/solutions/LEN-21561","name":"https://support.lenovo.com/us/en/solutions/LEN-21561","refsource":"CONFIRM","tags":["Mitigation","Vendor Advisory"],"title":"Lenovo Help Android App Access Control - Lenovo Support US","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-9067","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-9067","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"9067","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"lenovo_help","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9067","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"lenovo_help","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","DATE_PUBLIC":"2018-07-13T00:00:00","ID":"CVE-2018-9067","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Lenovo Help Android application","version":{"version_data":[{"version_value":"Earlier than 6.1.2.0327"}]}}]},"vendor_name":"Lenovo Group Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Exposure and modification of private app data"}]}]},"references":{"reference_data":[{"name":"https://support.lenovo.com/us/en/solutions/LEN-21561","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/solutions/LEN-21561"}]}},"nvd":{"publishedDate":"2018-07-13 16:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lenovo:lenovo_help:*:*:*:*:*:android:*:*","versionEndExcluding":"6.1.2.0327","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"9067","Ordinal":"125458","Title":"CVE-2018-9067","CVE":"CVE-2018-9067","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"9067","Ordinal":"1","NoteData":"The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"9067","Ordinal":"2","NoteData":"2018-07-13","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"9067","Ordinal":"3","NoteData":"2018-07-13","Type":"Other","Title":"Modified"}]}}}