Vulnerability Description
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | <= 5.1.1 | |
| Lenovo | Vibe A1600 | - |
| Lenovo | Vibe A2560 | - |
| Lenovo | Vibe A2800 | - |
| Lenovo | Vibe A2860 | - |
| Lenovo | Vibe A2880 | - |
| Lenovo | Vibe A3000 | - |
| Lenovo | Vibe A3500 | - |
| Lenovo | Vibe A3600-D | - |
| Lenovo | Vibe A3600U | - |
| Lenovo | Vibe A3800-D | - |
| Lenovo | Vibe A3900 | - |
| Lenovo | Vibe A6000 | - |
| Lenovo | Vibe A6000-I | - |
| Lenovo | Vibe A6020I37 | - |
| Lenovo | Vibe A6600 | - |
| Lenovo | Vibe A6800 | - |
| Lenovo | Vibe K30-E | - |
| Lenovo | Vibe K30-W-Cu | - |
| Lenovo | Vibe K32C30 | - |
References
- https://support.lenovo.com/us/en/product_security/LEN-15823MitigationVendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-15823MitigationVendor Advisory
FAQ
What is CVE-2017-3749?
CVE-2017-3749 is a vulnerability with a CVSS score of 6.4 (MEDIUM). On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in c...
How severe is CVE-2017-3749?
CVE-2017-3749 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3749?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Lenovo Vibe A1600, Lenovo Vibe A2560, Lenovo Vibe A2800, Lenovo Vibe A2860.