ID

VAR-201807-1684


CVE

CVE-2018-9070


TITLE

Lenovo Smart Assistant Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-007934

DESCRIPTION

For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo. Lenovo Smart Assistant Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. A security vulnerability exists in versions of the Lenovo Smart Assistant Android app prior to 12.1.82. Attackers in close proximity can exploit this vulnerability to enter factory detection mode and open web services and gain permissions (such as changing settings and running code)

Trust: 1.71

sources: NVD: CVE-2018-9070 // JVNDB: JVNDB-2018-007934 // VULHUB: VHN-139102

AFFECTED PRODUCTS

vendor:lenovomodel:smart assistantscope:ltversion:12.1.82

Trust: 1.8

sources: JVNDB: JVNDB-2018-007934 // NVD: CVE-2018-9070

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-9070
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-9070
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201807-1174
value: MEDIUM

Trust: 0.6

VULHUB: VHN-139102
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-9070
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-139102
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-9070
baseSeverity: MEDIUM
baseScore: 6.4
vectorString: CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.5
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-139102 // JVNDB: JVNDB-2018-007934 // CNNVD: CNNVD-201807-1174 // NVD: CVE-2018-9070

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-139102 // JVNDB: JVNDB-2018-007934 // NVD: CVE-2018-9070

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201807-1174

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201807-1174

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-007934

PATCH

title:LEN-22172url:https://support.lenovo.com/jp/ja/solutions/len-22172

Trust: 0.8

title:Lenovo Smart Assistant Android app Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=82137

Trust: 0.6

sources: JVNDB: JVNDB-2018-007934 // CNNVD: CNNVD-201807-1174

EXTERNAL IDS

db:NVDid:CVE-2018-9070

Trust: 2.5

db:LENOVOid:LEN-22172

Trust: 1.7

db:JVNDBid:JVNDB-2018-007934

Trust: 0.8

db:CNNVDid:CNNVD-201807-1174

Trust: 0.7

db:VULHUBid:VHN-139102

Trust: 0.1

sources: VULHUB: VHN-139102 // JVNDB: JVNDB-2018-007934 // CNNVD: CNNVD-201807-1174 // NVD: CVE-2018-9070

REFERENCES

url:https://support.lenovo.com/us/en/solutions/len-22172

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-9070

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-9070

Trust: 0.8

sources: VULHUB: VHN-139102 // JVNDB: JVNDB-2018-007934 // CNNVD: CNNVD-201807-1174 // NVD: CVE-2018-9070

SOURCES

db:VULHUBid:VHN-139102
db:JVNDBid:JVNDB-2018-007934
db:CNNVDid:CNNVD-201807-1174
db:NVDid:CVE-2018-9070

LAST UPDATE DATE

2024-11-23T22:17:25.732000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-139102date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-007934date:2018-10-02T00:00:00
db:CNNVDid:CNNVD-201807-1174date:2019-10-23T00:00:00
db:NVDid:CVE-2018-9070date:2024-11-21T04:14:54.773

SOURCES RELEASE DATE

db:VULHUBid:VHN-139102date:2018-07-13T00:00:00
db:JVNDBid:JVNDB-2018-007934date:2018-10-02T00:00:00
db:CNNVDid:CNNVD-201807-1174date:2018-07-16T00:00:00
db:NVDid:CVE-2018-9070date:2018-07-13T16:29:00.643