Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11341

Опубликовано: 09 окт. 2019
Источник: nvd
CVSS3: 4.6
CVSS2: 2.1
EPSS Низкий

Описание

On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*
cpe:2.3:h:samsung:phone:-:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00017
Низкий

4.6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 4.6
github
больше 3 лет назад

On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic.

EPSS

Процентиль: 3%
0.00017
Низкий

4.6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-327