Vulnerabilities > CVE-2016-1489 - 7PK - Security Features vulnerability in Lenovo Shareit 2.5.1.1/3.0.18Ww

047910
CVSS 8.0 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
high complexity
lenovo
CWE-254

Summary

Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Lenovo
2

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/135378/CORE-2016-0002.txt
idPACKETSTORM:135378
last seen2016-12-05
published2016-01-25
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/135378/Lenovo-ShareIT-Information-Disclosure-Hardcoded-Password.html
titleLenovo ShareIT Information Disclosure / Hardcoded Password

The Hacker News

idTHN:40215F710216890B071AFE57EBF264DD
last seen2018-01-27
modified2016-01-27
published2016-01-26
reporterSwati Khandelwal
sourcehttps://thehackernews.com/2016/01/shareit-file-sharing.html
titleOh Snap! Lenovo protects your Security with '12345678' as Hard-Coded Password in SHAREit