PT-2018-12856 · Asus+1 · Com.Asus.Loguploader+2

Publicado

2018-12-28

·

Atualizado

2019-02-22

·

CVE-2018-14979

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US Phone/ASUS X008 1:7.0/NRD90M/US Phone-14.14.1711.92-20171208:user/release-keys com.asus.loguploader version 7.0.0.55 170515
Description The pre-installed app com.asus.loguploader contains an exported service app component named com.asus.loguploader.LogUploaderService. When accessed with a particular action string, it writes sensitive data, including bug reports, Wi-Fi passwords, and system data, to external storage. Any app with the READ EXTERNAL STORAGE permission can read this data from the sdcard. This allows unauthorized access to sensitive information, as third-party apps are not supposed to directly create bug reports or access stored wireless network credentials.
Recommendations For ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US Phone/ASUS X008 1:7.0/NRD90M/US Phone-14.14.1711.92-20171208:user/release-keys, consider disabling the com.asus.loguploader.LogUploaderService to prevent sensitive data from being written to external storage. For com.asus.loguploader version 7.0.0.55 170515, restrict access to the external storage to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14979

Produtos afetados

Asus Zenfone 3 Max
Android
Com.Asus.Loguploader