Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g95-g4x3-wrvv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic.

On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic.

EPSS

Процентиль: 3%
0.00017
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 4.6
nvd
больше 6 лет назад

On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic.

EPSS

Процентиль: 3%
0.00017
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-327