Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16243

Опубликовано: 26 нояб. 2019
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:alcatelmobile:cingular_flip_2_firmware:b9huah1:*:*:*:*:*:*:*
cpe:2.3:h:alcatelmobile:cingular_flip_2:-:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00207
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

github
больше 3 лет назад

On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)

EPSS

Процентиль: 43%
0.00207
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-306