PT-2016-7459 · Samsung · Samsung Galaxy S5+4

Published

2016-10-31

·

Updated

2016-12-02

·

CVE-2016-7991

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Samsung Galaxy S series versions S4 through S7
Description The issue allows remote unsolicited WAP Push SMS messages to be accepted, parsed, and handled by the device, leading to unauthorized configuration changes. This occurs because the "omacp" app ignores security information embedded in the OMACP messages.
Recommendations For Samsung Galaxy S4 through S7 devices, consider disabling the "omacp" app until a patch is available to prevent unauthorized configuration changes. Restrict access to the device's configuration settings to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7991

Affected Products

Samsung Galaxy S4
Samsung Galaxy S5
Samsung Galaxy S6
Samsung Galaxy S7
Omacp