CVE-2017-3742 Vulnerability Details

  /     /     /  

CVE-2017-3742 Metadata Quick Info

CVE Published: 17/07/2017 | CVE Updated: 16/09/2024 | CVE Year: 2017
Source: lenovo | Vendor: Lenovo Group Ltd. | Product: Lenovo Connect2
Status : PUBLISHED

CVE-2017-3742 Description

In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user\'s contents could connect to the Connect2 hotspot and see the contents of files while they are being transferred between the two systems.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Disclosure of ad-hoc wifi network key stored in user-readable location
Source: Lenovo Group Ltd.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).