CVE-2016-1492: Medium severity shareit vulnerability
The Wifi hotspot in Lenovo SHAREit before 3.5.48ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1492?
CVE-2016-1492 is considered a high severity vulnerability due to its potential to allow unauthorized access to users' files.
How do I fix CVE-2016-1492?
To mitigate CVE-2016-1492, update Lenovo SHAREit to a version higher than 3.5.48_ww that includes password protection for the WiFi hotspot.
What types of attacks are possible due to CVE-2016-1492?
CVE-2016-1492 allows remote attackers within WLAN coverage to intercept files sent via SHAREit, leading to potential data leakage.
Which versions of Lenovo SHAREit are affected by CVE-2016-1492?
Lenovo SHAREit versions prior to 3.5.48_ww are affected by CVE-2016-1492 and lack password protection for the WiFi hotspot.
Is there a workaround for CVE-2016-1492?
A temporary workaround for CVE-2016-1492 is to disable the file receiving feature of the SHAREit app until an update is available.