Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-26627 Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-10T21:31:11.966Z

Reserved: 2022-12-29T03:00:40.880Z

Link: CVE-2023-22473

cve-icon Vulnrichment

Updated: 2024-08-02T10:13:48.470Z

cve-icon NVD

Status : Modified

Published: 2023-01-09T15:15:11.037

Modified: 2024-11-21T07:44:52.587

Link: CVE-2023-22473

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.