Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3720


An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.


Published

2021-11-12T22:15:08.007

Last Modified

2024-11-21T06:22:14.840

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-276
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo legion_phone_pro_\(l79031\)firmware < 12.5.231 Yes
Hardware lenovo legion_phone_pro_\(l79031\) - No
Operating System lenovo legion_phone2_pro_\(l70081\)_firmware < 12.5.632 Yes
Hardware lenovo legion_phone2_pro_\(l70081\) - No

References