← Back

CVE-2011-4872

nvd nist
Published: Feb 5, 2012Modified: Apr 29, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

Affected (10)

9 products
Desire Hd
Desire S
Droid Incredible
Evo 3d
Evo 4g
Glacier
Sensation 4g
Sensation Z710e
Thunderbolt 4g
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Htc
Version frg83d
Version gri40
Version gri40
Version frf91
Version gri40
Version gri40
Version frg83
Version gri40
Version gri40
Version frg83d

References (10)

Source: cret@cert.org
Vendor Advisory
Source: cret@cert.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.