Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvjp-3rj2-p4ww

Опубликовано: 29 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.

EPSS

Процентиль: 11%
0.00038
Низкий

3.1 Low

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 3.1
nvd
около 1 года назад

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.

EPSS

Процентиль: 11%
0.00038
Низкий

3.1 Low

CVSS3

Дефекты

CWE-306