PT-2019-14131 · Google+1 · Android+1

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15402

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asus ASUS A002 2 Android device with a build fingerprint of asus/WW ASUS A002 2/ASUS A002 2:7.0/NRD90M/14.1610.1802.18-20180321:user/release-keys
Description The issue concerns a pre-installed app with a package name of com.asus.loguploaderproxy that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device that can obtain signatureOrSystem permissions required by other pre-installed apps that exported their capabilities to other pre-installed apps.
Recommendations For the Asus ASUS A002 2 Android device, consider restricting access to the com.asus.loguploaderproxy app to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the accessible app component that allows command execution can help mitigate the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15402

Affected Products

Asus A002 2
Android