CVE-2016-4030
6.8
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version g920fxxu2coh2 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version n9005xxugbob6 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy Note 3 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version i9192xxubnb1 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 Mini | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version i9195xxucol1 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 Mini Lte | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version i9505xxuhoj2 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 | All versions |
References (4)
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Timeline
No history available yet.