Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change the device's settings, or spoof devices in other rooms.
History

Mon, 30 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Android App
Android App smart Tab
CPEs cpe:2.3:a:android_app:smart_tab:*:*:*:*:*:*:*:*
Vendors & Products Android App
Android App smart Tab
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 08:00:00 +0000

Type Values Removed Values Added
Description Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change the device's settings, or spoof devices in other rooms.
Weaknesses CWE-489
References
Metrics cvssV3_0

{'score': 6.8, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-09-30T07:50:34.536Z

Updated: 2024-09-30T16:45:01.184Z

Reserved: 2024-09-18T23:09:30.952Z

Link: CVE-2024-41999

cve-icon Vulnrichment

Updated: 2024-09-30T16:44:53.845Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-30T08:15:03.210

Modified: 2024-09-30T17:35:09.340

Link: CVE-2024-41999

cve-icon Redhat

No data.