PT-2016-7459 · Samsung · Samsung Galaxy S5+4
Publicado
2016-10-31
·
Atualizado
2016-12-02
·
CVE-2016-7991
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Galaxy S series versions S4 through S7
Description
The issue allows remote unsolicited WAP Push SMS messages to be accepted, parsed, and handled by the device, leading to unauthorized configuration changes. This occurs because the "omacp" app ignores security information embedded in the OMACP messages.
Recommendations
For Samsung Galaxy S4 through S7 devices, consider disabling the "omacp" app until a patch is available to prevent unauthorized configuration changes. Restrict access to the device's configuration settings to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Samsung Galaxy S4
Samsung Galaxy S5
Samsung Galaxy S6
Samsung Galaxy S7
Omacp