CVE Database
/

CVE-2017-3760

Back to search

CVE-2017-3760

Published: Oct 17, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.

VendorProductVersions

Lenovo Group Ltd.

Service Framework application

affected
various versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now