CVE-2020-5571
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQUOS mini SH-M03 build number 01.00.04 and earlier, AQUOS Keitai SH-N01 build number 01.00.01 and earlier, AQUOS L2 (UQ mobile/J:COM) build number 01.00.05 and earlier, AQUOS sense lite SH-M05 build number 03.00.04 and earlier, AQUOS sense (UQ mobile) build number 03.00.03 and earlier, AQUOS compact SH-M06 build number 02.00.02 and earlier, AQUOS sense plus SH-M07 build number 02.00.02 and earlier, AQUOS sense2 SH-M08 build number 02.00.05 and earlier, and AQUOS sense2 (UQ mobile) build number 02.00.06 and earlier) allow an attacker to obtain the sensitive information of the device via malicious applications installed on the device.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.00.05 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sh M02 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.00.04 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sh Rm02 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.00.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.00.01 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Mini Sh M03 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.00.05 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos L2 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 03.00.04 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sense Lite Sh M05 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 03.00.03 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sense | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.00.02 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Compact Sh M06 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 0.2.00.02 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sense Plus Sh M07 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.00.05 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sense2 Sh M08 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.00.06 |
| Running on/with | Platform Versions |
|---|---|
Sharp Aquos Sense2 | All versions |
References (4)
Source: vultures@jpcert.or.jp
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.