Vulnerability CVE-2021-41181


Published: 2022-03-08

Description:
Nextcloud talk is a self hosting messaging service. In versions prior to 12.3.0 the Nextcloud Android Talk application did not properly detect the lockscreen state when a call was incoming. If an attacker got physical access to the locked phone, and the victim received a phone call the attacker could gain access to the chat messages and files of the user. It is recommended that the Nextcloud Android Talk App is upgraded to 12.3.0. There are no known workarounds.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Nextcloud -> TALK 

 References:
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-497c-c8hx-6qcf
https://github.com/nextcloud/talk-android/pull/1585

Copyright 2024, cxsecurity.com

 

Back to Top