« Volver al listado

CVE-2021-3720

Estado: ModificadaMedia (5.5)—

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-3720",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@lenovo.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@lenovo.com",
      "affectedData": [
        {
          "vendor": "Lenovo",
          "product": "Legion Phone Pro (L79031)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "12.5.231",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Lenovo",
          "product": "Legion Phone2 Pro (L70081)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "12.5.632",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-12T22:15:08.007",
  "references": [
    {
      "url": "https://iknow.lenovo.com.cn/detail/dc_199217.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@lenovo.com"
    },
    {
      "url": "https://iknow.lenovo.com.cn/detail/dc_199217.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@lenovo.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data."
    },
    {
      "lang": "es",
      "value": "Se ha informado de una vulnerabilidad de divulgación de información en el widget del sistema Time Weather en Legion Phone Pro (L79031) y Legion Phone2 Pro (L70081) que podría permitir a otras aplicaciones acceder a los datos del GPS del dispositivo"
    }
  ],
  "lastModified": "2026-06-17T04:05:38.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:legion_phone_pro_\\(l79031\\)firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36A91A6C-44DE-406F-92BB-FFFC787F09EB",
              "versionEndExcluding": "12.5.231"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:legion_phone_pro_\\(l79031\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A2B1693-72A3-45B0-9496-D57B373CE66E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:legion_phone2_pro_\\(l70081\\)_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72FBE839-AA26-4DC8-8B79-9A1A9B00AF2B",
              "versionEndExcluding": "12.5.632"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:legion_phone2_pro_\\(l70081\\):-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3C03E10A-B58D-479C-88E4-B6265DAC4FCC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@lenovo.com"
}