CVE-2023-42579
5.3
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD
Description
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
Affected (7)
Products: Samsung: Samsung Keyboard
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.4.60.0 to 5.4.60.49 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 11.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.6.00.0 to 5.6.00.52 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 12.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.70.1 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 13.0 |
References (2)
Source: mobile.security@samsung.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.