PT-2018-17660 · Google+1 · Android Open Source Project+2
Published
2018-08-29
·
Updated
2019-10-03
·
CVE-2018-6598
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Orbic Wonder Orbic/RC555L version 7.1.2
Description
An issue allows any co-located app to send an intent to
com.android.server.MasterClearReceiver to factory reset the device programmatically without requiring user interaction or permission. This results in the loss of all user data not backed up or synced externally. The capability to perform a factory reset is not directly available to third-party apps but is present in an unprotected component of the Android OS. This issue is not present in Google's Android Open Source Project (AOSP) code, indicating it was introduced by Orbic or another entity in the supply chain.Recommendations
For Orbic Wonder Orbic/RC555L version 7.1.2, consider restricting access to the
com.android.server.MasterClearReceiver component to prevent unauthorized factory resets until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Os
Android Open Source Project
Orbic Wonder Orbic/Rc555L