PT-2018-13078 · Telegram · Org.Telegram.Messenger

Boonpoj Thongakaraniroj

+1

·

Publicado

2018-10-09

·

Atualizado

2024-08-05

·

CVE-2018-15542

CVSS v3.1

6.4

Média

VetorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions org.telegram.messenger application version 4.8.11
Description The issue allows authentication bypass via runtime manipulation that forces a certain method's return value to true, enabling an attacker to authenticate with an arbitrary passcode. The vendor notes that this is not considered an attack of interest within their threat model, specifically excluding Android devices on which rooting has occurred.
Recommendations For version 4.8.11, consider disabling the Passcode feature until a patch is available to prevent potential authentication bypass.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15542

Produtos afetados

Org.Telegram.Messenger