PT-2019-14157 · Google+1 · Android+2
Published
2019-11-14
·
Updated
2019-11-25
·
CVE-2019-15428
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Xiaomi Mi Note 2 Android device with a build fingerprint of Xiaomi/scorpio/scorpio:6.0.1/MXB48T/7.1.5:user/release-keys
com.miui.powerkeeper app version 4.0.00
Description
The issue allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.
Recommendations
For the Xiaomi Mi Note 2 Android device, consider restricting access to the com.miui.powerkeeper app until a patch is available.
For the com.miui.powerkeeper app version 4.0.00, avoid using the app to modify wireless settings until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Xiaomi Mi Note 2
Com.Miui.Powerkeeper