CVE-2016-4032
4.6
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD
Description
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify Android settings by leveraging AT access, aka SVE-2016-5301.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version g920fxxu2coh2 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version n9005xxugbob6 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy Note 3 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version i9192xxubnb1 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 Mini | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version i9195xxucol1 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 Mini Lte | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version i9505xxuhoj2 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S4 | All versions |
References (4)
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Timeline
No history available yet.