Описание
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sktelecom:com.skt.prod.dialer:12.5.0:*:*:*:*:android:*:*
EPSS
Процентиль: 3%
0.00017
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 4.3
github
7 месяцев назад
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
EPSS
Процентиль: 3%
0.00017
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-862