Description
The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.
Published: 2012-05-01
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2012-2211 The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.
History

No history.

Subscriptions

Htc Evo 3d Evo 3d Software Evo 4g Evo 4g Software Evo Design 4g Evo Design 4g Software Evo View 4g Evo View 4g Software Hero Hero Software Shift 4g Shift 4g Software Vivid Vivid Software
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T19:26:08.929Z

Reserved: 2012-04-10T00:00:00.000Z

Link: CVE-2012-2217

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-05-01T14:55:01.673

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-2217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses