PT-2020-7917 · Samsung · Samsung Mobile Devices
Published
2020-04-10
·
Updated
2020-04-13
·
CVE-2015-9546
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Samsung mobile devices with KK(4.4) and later software through 2015-06-16
Description:
An issue was discovered where HTTP is used for an Inputmethod, rather than HTTPS, allowing a man-in-the-middle attacker to modify the client-server data stream and insert directory traversal sequences into an extracted file path.
Recommendations:
For Samsung mobile devices with KK(4.4) and later software through 2015-06-16, consider disabling the use of HTTP for Inputmethod until a secure connection method, such as HTTPS, is implemented. Restrict access to sensitive data and functions to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Mobile Devices