CVE-2011-4872
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD
Description
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
Affected (10)
Products: Htc: Desire Hd, Desire S, Droid Incredible, Evo 3d, Evo 4g, Glacier, Sensation 4g, Sensation Z710e, Thunderbolt 4g
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version frg83d | |
| Version gri40 | |
| Version frf91 | |
| Version gri40 | |
| Version gri40 | |
| Version frg83 | |
| Version gri40 | |
| Version gri40 | |
| Version frg83d |
References (10)
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.