CVE Published: 17/10/2017 |
CVE Updated: 16/09/2024 |
CVE Year: 2017 Source: lenovo |
Vendor: Lenovo Group Ltd. |
Product: Service Framework application Status : PUBLISHED
CVE-2017-3760 Description
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.