PT-2018-11178 · Dropbox · Com.Dropbox.Android

Boonpoj Thongakaraniroj

+1

·

Publicado

2018-06-20

·

Atualizado

2024-08-05

·

CVE-2018-12445

CVSS v2.0

3.3

Baixa

VetorAV:L/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions com.dropbox.android version 98.2.2
Description An issue in the com.dropbox.android application allows authentication bypass through the FingerprintManager class for Biometric validation. This is possible because the fingerprint API, in conjunction with the Android keyGenerator class, is not properly implemented, enabling an attacker to authenticate with an arbitrary fingerprint. The vendor notes that this issue is not considered a threat within their threat model, specifically excluding Android devices that have been rooted.
Recommendations For version 98.2.2, consider disabling the FingerprintManager class for Biometric validation until a proper fix is implemented to prevent authentication bypass. Restrict access to the fingerprint API to minimize the risk of exploitation. Avoid using the fingerprint authentication method in the affected application until the issue is resolved.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12445

Produtos afetados

Com.Dropbox.Android