Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7x3-mc24-pxm6

Опубликовано: 17 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions.

Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6

Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions.

Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6

EPSS

Процентиль: 6%
0.00025
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-926

Связанные уязвимости

nvd
7 месяцев назад

Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions. Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6

EPSS

Процентиль: 6%
0.00025
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-926