MEDIUM · 5.5

CVE-2021-3720

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device ...

Vulnerability Description

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LenovoLegion Phone Pro \(L79031\)Firmware< 12.5.231
LenovoLegion Phone Pro \(L79031\)-
LenovoLegion Phone2 Pro \(L70081\) Firmware< 12.5.632
LenovoLegion Phone2 Pro \(L70081\)-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3720?

CVE-2021-3720 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device ...

How severe is CVE-2021-3720?

CVE-2021-3720 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3720?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Legion Phone Pro \(L79031\)Firmware, Lenovo Legion Phone Pro \(L79031\), Lenovo Legion Phone2 Pro \(L70081\) Firmware, Lenovo Legion Phone2 Pro \(L70081\).