Lucene search

K
cve[email protected]CVE-2021-3720
HistoryNov 12, 2021 - 10:15 p.m.

CVE-2021-3720

2021-11-1222:15:08
CWE-276
web.nvd.nist.gov
22
cve-2021-3720
information disclosure
vulnerability
time weather
legion phone pro
legion phone2 pro
gps data
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.

Affected configurations

NVD
Node
lenovolegion_phone_pro_\(l79031\)firmwareRange<12.5.231
AND
lenovolegion_phone_pro_\(l79031\)Match-
Node
lenovolegion_phone2_pro_\(l70081\)_firmwareRange<12.5.632
AND
lenovolegion_phone2_pro_\(l70081\)Match-

CNA Affected

[
  {
    "product": "Legion Phone Pro (L79031)",
    "vendor": "Lenovo",
    "versions": [
      {
        "lessThan": "12.5.231",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Legion Phone2 Pro (L70081)",
    "vendor": "Lenovo",
    "versions": [
      {
        "lessThan": "12.5.632",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

Related for CVE-2021-3720