PT-2016-7459 · Samsung · Samsung Galaxy S5+4
Published
2016-10-31
·
Updated
2016-12-02
·
CVE-2016-7991
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Galaxy S series versions S4 through S7
Description
The issue allows remote unsolicited WAP Push SMS messages to be accepted, parsed, and handled by the device, leading to unauthorized configuration changes. This occurs because the "omacp" app ignores security information embedded in the OMACP messages.
Recommendations
For Samsung Galaxy S4 through S7 devices, consider disabling the "omacp" app until a patch is available to prevent unauthorized configuration changes. Restrict access to the device's configuration settings to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Galaxy S4
Samsung Galaxy S5
Samsung Galaxy S6
Samsung Galaxy S7
Omacp