PT-2020-8552 · Samsung · Tizen+1

Published

2020-01-22

·

Updated

2020-01-30

·

CVE-2018-16271

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: wemail consumer service versions prior to build RE2
Description: The issue arises from improper D-Bus security policy configurations in the wemail consumer service, part of the built-in wemail application on Samsung Galaxy Gear series devices. This allows an unprivileged process to manipulate a user's mailbox. Furthermore, it enables the sending of arbitrary emails from the mailbox via the paired smartphone. This issue affects devices running Tizen-based firmwares, specifically Samsung Galaxy Gear series devices before build RE2.
Recommendations: For versions prior to build RE2, update the firmware to a version that includes the necessary security policy configurations to prevent unprivileged processes from manipulating the mailbox. As a temporary workaround, consider restricting access to the wemail consumer service to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16271

Affected Products

Tizen
Wemail Consumer Service