The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-12878 | The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-15374 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-17T03:29:06.189Z
Reserved: 2016-12-16T00:00:00
Link: CVE-2017-3761
No data.
Status : Deferred
Published: 2017-10-17T20:29:00.370
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-3761
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD