CVE-2018-9070 Information
Feb 14, 2021
cve
Description
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82 an attacker with physical access to the smart speaker can by pressing a specific button sequence enter factory test mode and enable a web service intended for testing the device. As with most test modes this provides extra privileges including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.
CVSS Vector
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://support.lenovo.com/us/en/solutions/LEN-22172
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.4
Share on: