PT-2018-13078 · Telegram · Org.Telegram.Messenger
Boonpoj Thongakaraniroj
+1
·
Publicado
2018-10-09
·
Atualizado
2024-08-05
·
CVE-2018-15542
CVSS v3.1
6.4
Média
| Vetor | AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
org.telegram.messenger application version 4.8.11
Description
The issue allows authentication bypass via runtime manipulation that forces a certain method's return value to
true, enabling an attacker to authenticate with an arbitrary passcode. The vendor notes that this is not considered an attack of interest within their threat model, specifically excluding Android devices on which rooting has occurred.Recommendations
For version 4.8.11, consider disabling the Passcode feature until a patch is available to prevent potential authentication bypass.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Org.Telegram.Messenger