CVE-2015-4640
2.9
Vector
AV:A/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 5.5 / Impact: 2.9
Source: NVD
Description
The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP connection to the skslm.swiftkey.net server, which allows man-in-the-middle attackers to write to language-pack files by modifying an HTTP response. NOTE: CVE-2015-4640 exploitation can be combined with CVE-2015-4641 exploitation for man-in-the-middle code execution.
Affected (1)
Products: Swiftkey: Swiftkey Sdk
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 | All versions |
Samsung Galaxy S4 Mini | All versions |
Samsung Galaxy S5 | All versions |
Samsung Galaxy S6 | All versions |
Related CWEs
References (12)
Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Timeline
No history available yet.