PT-2017-2428 · Google+1 · Android+1
Publicado
2017-06-30
·
Atualizado
2019-10-03
·
CVE-2017-10709
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Elephone P9000 devices running Android 6.0
Description
The issue concerns a security flaw in the lockscreen component of the Android operating system, specifically related to errors in security settings. This flaw allows a physically proximate attacker to bypass the wrong-PIN lockout feature. The attacker can exploit this by pressing the backspace key after each PIN guess, thereby circumventing the lockout mechanism.
Recommendations
For Elephone P9000 devices running Android 6.0, consider disabling the lockscreen feature until a patch is available, or avoid using the PIN lock feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Android
Elephone P9000