Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9j3f-94w3-hrhc

Опубликовано: 13 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop by all third-party applications co-located on the device, even those with no permissions granted, exposing the IMEI values to processes without enforcing any access control.

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop by all third-party applications co-located on the device, even those with no permissions granted, exposing the IMEI values to processes without enforcing any access control.

EPSS

Процентиль: 36%
0.00149
Низкий

7.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop by all third-party applications co-located on the device, even those with no permissions granted, exposing the IMEI values to processes without enforcing any access control.

EPSS

Процентиль: 36%
0.00149
Низкий

7.8 High

CVSS3

Дефекты

CWE-863