High severity7.5NVD Advisory· Published Jun 20, 2017· Updated May 13, 2026
CVE-2017-3743
CVE-2017-3743
Description
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.
Affected products
4- cpe:2.3:a:lenovo:updatexpress_system_pack_installer:*:*:*:*:*:*:*:*Range: <=10.2
- cpe:2.3:a:lenovo:advanced_settings_utility:*:*:*:*:*:*:*:*Range: <=10.1
- cpe:2.3:a:lenovo:toolscenter_dynamic_system_analysis:*:*:*:*:*:*:*:*Range: <=10.2
- Lenovo Group Ltd./ToolsCenterv5Range: Lenovo Advanced Settings Utility versions earlier than 10.2 and UXSPI and DSA versions earlier than 10.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- support.lenovo.com/us/en/product_security/LEN-10810nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.