- Description
- An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.
- Source
- psirt@lenovo.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
- psirt@lenovo.com
- CWE-276
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lenovo:legion_phone_pro_\\(l79031\\)firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36A91A6C-44DE-406F-92BB-FFFC787F09EB",
"versionEndExcluding": "12.5.231"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lenovo:legion_phone_pro_\\(l79031\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9A2B1693-72A3-45B0-9496-D57B373CE66E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lenovo:legion_phone2_pro_\\(l70081\\)_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72FBE839-AA26-4DC8-8B79-9A1A9B00AF2B",
"versionEndExcluding": "12.5.632"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lenovo:legion_phone2_pro_\\(l70081\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3C03E10A-B58D-479C-88E4-B6265DAC4FCC"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]