Description
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
Published: 2023-12-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-47012 Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
History

No history.

Subscriptions

Google Android
Samsung Samsung Keyboard
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2024-08-02T19:23:40.156Z

Reserved: 2023-09-11T23:55:08.357Z

Link: CVE-2023-42579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-05T03:15:18.967

Modified: 2024-11-21T08:22:49.837

Link: CVE-2023-42579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses