Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phgf-8v5r-r8p3

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.4

Описание

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions. 

After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions. 

After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.

EPSS

Процентиль: 10%
0.00036
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-925

Связанные уязвимости

nvd
около 1 года назад

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.  After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.

EPSS

Процентиль: 10%
0.00036
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-925