PT-2020-12809 · Cellebrite+1 · Cellebrite Ufed+1

Published

2020-04-14

·

Updated

2020-04-22

·

CVE-2020-11723

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cellebrite UFED versions 5.0 through 7.29
Description The issue concerns the use of hardcoded RSA private keys for authentication to the ADB daemon on target devices. These extracted keys can potentially be used to compromise the integrity of forensic extractions by allowing unauthorized access to place evidence onto target devices.
Recommendations For versions 5.0 through 7.29, consider disabling the use of hardcoded RSA private keys for authentication to the ADB daemon as a temporary mitigation measure. Restrict access to the ADB daemon to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11723

Affected Products

Adb
Cellebrite Ufed