PT-2020-8691 · Samsung · Samsung Mobile Devices
Published
2020-04-08
·
Updated
2020-04-09
·
CVE-2018-21047
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung mobile devices with O(8.x) software
Description
An issue allows for a Factory Reset Protection (FRP) bypass via the voice assistant on affected devices. This occurs because Internet access is granted before the Setup Wizard is completed.
Recommendations
For Samsung mobile devices with O(8.x) software, as a temporary workaround, consider disabling the voice assistant until a patch is available. Restrict access to Internet services before completing the Setup Wizard to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Mobile Devices