PT-2012-3889 · Htc+1 · Evo View 4G+6

Published

2012-05-01

·

Updated

2017-12-14

·

CVE-2012-2217

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions HTC IQRD service for Android on the HTC EVO 4G versions prior to 4.67.651.3 HTC IQRD service for Android on the EVO Design 4G versions prior to 2.12.651.5 HTC IQRD service for Android on the Shift 4G versions prior to 2.77.651.3 HTC IQRD service for Android on the EVO 3D versions prior to 2.17.651.5 HTC IQRD service for Android on the EVO View 4G versions prior to 2.23.651.1 HTC IQRD service for Android on the Vivid versions prior to 3.26.502.56
Description The issue allows remote attackers to send SMS messages, obtain the Network Access Identifier (NAI) and its password, trigger popup messages, or tones via a crafted application that leverages the android.permission.INTERNET permission, due to the lack of restriction on localhost access to TCP port 2479.
Recommendations For HTC EVO 4G versions prior to 4.67.651.3, update to version 4.67.651.3 or later. For EVO Design 4G versions prior to 2.12.651.5, update to version 2.12.651.5 or later. For Shift 4G versions prior to 2.77.651.3, update to version 2.77.651.3 or later. For EVO 3D versions prior to 2.17.651.5, update to version 2.17.651.5 or later. For EVO View 4G versions prior to 2.23.651.1, update to version 2.23.651.1 or later. For Vivid versions prior to 3.26.502.56, update to version 3.26.502.56 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2217

Affected Products

Android
Evo 3D
Evo Design 4G
Evo View 4G
Htc Evo 4G
Shift 4G
Vivid