Vulnerability CVE-2012-2217


Published: 2012-05-01

Description:
The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
HTC IQRD Android Permission Leakage
Dan Rosenberg
22.04.2012

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
HTC -> Evo 4g software 
HTC -> Evo 4g 
HTC -> Evo 3d software 
HTC -> Evo design 4g software 
HTC -> Evo view 4g software 
HTC -> Hero software 
HTC -> Shift 4g software 
HTC -> Vivid software 
HTC -> Evo 3d 
HTC -> Evo design 4g 
HTC -> Evo view 4g 
HTC -> HERO 
HTC -> Shift 4g 
HTC -> Vivid 

 References:
http://archives.neohapsis.com/archives/bugtraq/2012-04/0176.html
http://www.securityfocus.com/bid/53187
http://www.vsecurity.com/resources/advisory/20120420-1/
https://exchange.xforce.ibmcloud.com/vulnerabilities/75080

Copyright 2024, cxsecurity.com

 

Back to Top