PT-2019-18304 · Samsung · Samsung Knox
James Dean
·
Publicado
2019-05-29
·
Atualizado
2024-12-22
·
CVE-2019-6744
CVSS v3.1
4.3
Média
| Vetor | AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Knox version 1.2.02.39
Description
This issue allows local attackers to disclose sensitive information on affected installations. An attacker must first obtain physical access to the device to exploit this. The flaw exists within the handling of the lock screen for Secure Folder, resulting from the lack of proper validation that a user has correctly authenticated. This can be leveraged to disclose the contents of the secure container.
Recommendations
For Samsung Knox version 1.2.02.39, consider disabling the lock screen feature for Secure Folder until a patch is available to prevent exploitation. Restrict physical access to devices to minimize the risk of this issue being exploited.
Correção
Improper Access Control
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Samsung Knox