Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxgp-vx99-mxcw

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

EPSS

Процентиль: 1%
0.00012
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-348

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

CVSS3: 4.3
nvd
2 месяца назад

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

CVSS3: 4.3
debian
2 месяца назад

In the KDE Connect information-exchange protocol before 2025-04-18, a ...

EPSS

Процентиль: 1%
0.00012
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-348