Vulnerabilities > CVE-2016-1491 - Credentials Management vulnerability in Lenovo Shareit 2.5.1.1

047910
CVSS 8.8 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
lenovo
CWE-255

Summary

The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

Vulnerable Configurations

Part Description Count
Application
Lenovo
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/135378/CORE-2016-0002.txt
idPACKETSTORM:135378
last seen2016-12-05
published2016-01-25
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/135378/Lenovo-ShareIT-Information-Disclosure-Hardcoded-Password.html
titleLenovo ShareIT Information Disclosure / Hardcoded Password

The Hacker News

idTHN:40215F710216890B071AFE57EBF264DD
last seen2018-01-27
modified2016-01-27
published2016-01-26
reporterSwati Khandelwal
sourcehttps://thehackernews.com/2016/01/shareit-file-sharing.html
titleOh Snap! Lenovo protects your Security with '12345678' as Hard-Coded Password in SHAREit