LiveActive security incident?Get immediate response
CVE Record

CVE-2017-3743: If multiple users are concurrently logged into a single system where one user is sending a command via the...

If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw can expose credentials used by Lenovo management tools when several users are logged into the same system. While one user runs a command against another machine, other local users may see the target system user ID and cleartext password during processing.

Executive priority

Treat this as a targeted administrative exposure issue, not an internet-scale emergency. Prioritize environments using legacy Lenovo management tooling on shared admin systems, because exposed credentials could enable follow-on access.

Technical view

CVE-2017-3743 affects Lenovo Advanced Settings Utility before 10.2 and UXSPI/DSA before 10.3. The issue is a local, concurrent-session credential disclosure during remote command processing. Sources do not provide CVSS, CWE, proof of exploitation, or broader product impact.

Likely exposure

Exposure is most likely on administrative workstations or servers where Lenovo ASU, UXSPI, or DSA are installed and multiple users can be logged in concurrently.

Exploitation context

No active exploitation is identified in the provided sources, and the CVE is not listed as KEV. The scenario requires concurrent local users and an administrator running affected Lenovo tooling with credentials.

Researcher notes

The public bundle supports credential disclosure under specific concurrency conditions only. It does not include CVSS, CWE, exploit details, or logs/artifacts for detection. Avoid expanding scope beyond ASU, UXSPI, and DSA versions named by Lenovo/CVE sources.

Mitigation direction

  • Upgrade ASU to 10.2 or later.
  • Upgrade UXSPI and DSA to 10.3 or later.
  • Review Lenovo advisory LEN-10810 for current vendor guidance.
  • Restrict concurrent local logins on administrative systems.
  • Rotate credentials if exposure during affected tool use is suspected.

Validation and detection

  • Inventory ASU, UXSPI, and DSA installations and versions.
  • Confirm ASU is 10.2 or later.
  • Confirm UXSPI and DSA are 10.3 or later.
  • Identify shared admin systems allowing concurrent interactive logins.
  • Review historical use for affected tools and exposed credentials.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2017-3743 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Lenovo Group Ltd.ToolsCenterLenovo Advanced Settings Utility versions earlier than 10.2 and UXSPI and DSA versions earlier than 10.3Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.