« Back to list

CVE-2018-9067

Status: ModifiedHigh (7.5)—

The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2018-9067",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@lenovo.com",
      "affectedData": [
        {
          "vendor": "Lenovo Group Ltd.",
          "product": "Lenovo Help Android application",
          "versions": [
            {
              "status": "affected",
              "version": "Earlier than 6.1.2.0327"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-07-13T16:29:00.613",
  "references": [
    {
      "url": "https://support.lenovo.com/us/en/solutions/LEN-21561",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "psirt@lenovo.com"
    },
    {
      "url": "https://support.lenovo.com/us/en/solutions/LEN-21561",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI."
    },
    {
      "lang": "es",
      "value": "La aplicación para Android Lenovo Help en versiones anteriores a la 6.1.2.0327 tenía un control de accesos insuficiente para algunas funciones que, si se hubiesen explotado, podrían haber conducido a la exposición de, aproximadamente, 400 direcciones de email y 8.500 códigos IMEI."
    }
  ],
  "lastModified": "2026-06-17T02:06:01.123",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:lenovo:lenovo_help:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A869A271-D42E-43A6-9AEA-2D2FB6EA681E",
              "versionEndExcluding": "6.1.2.0327"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@lenovo.com"
}