CVE-2017-3742 - CVE House
Back to Database
Status published Medium CVE-2017-3742

In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and...

Vulnerability Description

In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents could connect to the Connect2 hotspot and see the contents of files while they are being transferred between the two systems.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3742

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Lenovo Group Ltd.

View all reports →

Affected Software

Lenovo Connect2
Vulnerable Versions:
Earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android.

Timeline

Official Publish: July 17th, 2017
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.