PT-2012-6154 · Samsung · Samsung Kies Air

Published

2012-12-03

·

Updated

2017-08-29

·

CVE-2012-5858

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Kies Air versions 2.1.207051 through 2.1.210161
Description The issue allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address, as the software relies on the IP address for authentication.
Recommendations For Samsung Kies Air versions 2.1.207051 through 2.1.210161, consider implementing additional authentication mechanisms to prevent IP address spoofing attacks, such as using secure tokens or credentials. As a temporary workaround, restrict access to the network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5858

Affected Products

Samsung Kies Air