Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8g86-97w6-2547

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.

The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.

EPSS

Процентиль: 41%
0.00192
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 4.6
nvd
около 8 лет назад

The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.

EPSS

Процентиль: 41%
0.00192
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-306