Vulnerability Description
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Smart Assistant | < 12.1.82 |
References
- https://support.lenovo.com/us/en/solutions/LEN-22172MitigationVendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-22172MitigationVendor Advisory
FAQ
What is CVE-2018-9070?
CVE-2018-9070 is a vulnerability with a CVSS score of 6.4 (MEDIUM). For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and...
How severe is CVE-2018-9070?
CVE-2018-9070 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9070?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Smart Assistant.