Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3748


On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).


Published

2017-06-29T15:29:00.207

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System google android ≤ 5.1.1 Yes
Hardware lenovo vibe_a1600 - No
Hardware lenovo vibe_a2560 - No
Hardware lenovo vibe_a2800 - No
Hardware lenovo vibe_a2860 - No
Hardware lenovo vibe_a2880 - No
Hardware lenovo vibe_a3000 - No
Hardware lenovo vibe_a3500 - No
Hardware lenovo vibe_a3600-d - No
Hardware lenovo vibe_a3600u - No
Hardware lenovo vibe_a3800-d - No
Hardware lenovo vibe_a3900 - No
Hardware lenovo vibe_a6000 - No
Hardware lenovo vibe_a6000-i - No
Hardware lenovo vibe_a6020i37 - No
Hardware lenovo vibe_a6600 - No
Hardware lenovo vibe_a6800 - No
Hardware lenovo vibe_k30-e - No
Hardware lenovo vibe_k30-w-cu - No
Hardware lenovo vibe_k32c30 - No
Hardware lenovo vibe_k80m - No

References