PT-2020-8552 · Samsung · Tizen+1
Published
2020-01-22
·
Updated
2020-01-30
·
CVE-2018-16271
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
wemail consumer service versions prior to build RE2
Description:
The issue arises from improper D-Bus security policy configurations in the wemail consumer service, part of the built-in wemail application on Samsung Galaxy Gear series devices. This allows an unprivileged process to manipulate a user's mailbox. Furthermore, it enables the sending of arbitrary emails from the mailbox via the paired smartphone. This issue affects devices running Tizen-based firmwares, specifically Samsung Galaxy Gear series devices before build RE2.
Recommendations:
For versions prior to build RE2, update the firmware to a version that includes the necessary security policy configurations to prevent unprivileged processes from manipulating the mailbox. As a temporary workaround, consider restricting access to the wemail consumer service to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tizen
Wemail Consumer Service