Skip to content
appaloosa scout logo main rounded
CRITICAL 9.8

CVE-2017-3761

The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
lenovo service_framework Android cpe:2.3:a:lenovo:service_framework:-:*:*:*:*:android:*:*
View on NVD ↗