Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3749


On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.


Published

2017-06-29T15:29:00.237

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System google android ≤ 5.1.1 Yes
Hardware lenovo vibe_a1600 - No
Hardware lenovo vibe_a2560 - No
Hardware lenovo vibe_a2800 - No
Hardware lenovo vibe_a2860 - No
Hardware lenovo vibe_a2880 - No
Hardware lenovo vibe_a3000 - No
Hardware lenovo vibe_a3500 - No
Hardware lenovo vibe_a3600-d - No
Hardware lenovo vibe_a3600u - No
Hardware lenovo vibe_a3800-d - No
Hardware lenovo vibe_a3900 - No
Hardware lenovo vibe_a6000 - No
Hardware lenovo vibe_a6000-i - No
Hardware lenovo vibe_a6020i37 - No
Hardware lenovo vibe_a6600 - No
Hardware lenovo vibe_a6800 - No
Hardware lenovo vibe_k30-e - No
Hardware lenovo vibe_k30-w-cu - No
Hardware lenovo vibe_k32c30 - No
Hardware lenovo vibe_k80m - No

References