Vulnerabilities (CVE)

Filtered by vendor Lenovo Subscribe
Filtered by product Service Framework
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-3760 1 Lenovo 1 Service Framework 2019-10-03 5.1 MEDIUM 8.1 HIGH
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
CVE-2017-3759 1 Lenovo 1 Service Framework 2017-11-08 6.8 MEDIUM 8.1 HIGH
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.