Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw53-3g7g-86j9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have an information leak vulnerability due to improper file permission configuration. An attacker tricks a user into installing a malicious application on the smart phone, and the application can get the file that keep the cipher text of the SIM card PIN.

Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have an information leak vulnerability due to improper file permission configuration. An attacker tricks a user into installing a malicious application on the smart phone, and the application can get the file that keep the cipher text of the SIM card PIN.

EPSS

Процентиль: 26%
0.00092
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
nvd
около 8 лет назад

Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have an information leak vulnerability due to improper file permission configuration. An attacker tricks a user into installing a malicious application on the smart phone, and the application can get the file that keep the cipher text of the SIM card PIN.

EPSS

Процентиль: 26%
0.00092
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200