High severity7.5NVD Advisory· Published Jun 20, 2017· Updated Jun 17, 2026
CVE-2017-3743
CVE-2017-3743
Description
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.
Affected products
4- cpe:2.3:a:lenovo:advanced_settings_utility:*:*:*:*:*:*:*:*Range: <=10.1
- cpe:2.3:a:lenovo:toolscenter_dynamic_system_analysis:*:*:*:*:*:*:*:*Range: <=10.2
- cpe:2.3:a:lenovo:updatexpress_system_pack_installer:*:*:*:*:*:*:*:*Range: <=10.2
- Lenovo Group Ltd./ToolsCenterv5Range: Lenovo Advanced Settings Utility versions earlier than 10.2 and UXSPI and DSA versions earlier than 10.3
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/product_security/LEN-10810nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.