PT-2020-8699 · Qualcomm+1 · Msm8996+1
Published
2020-04-08
·
Updated
2020-04-13
·
CVE-2018-21055
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software
Description
An issue was discovered on Samsung mobile devices, allowing a device to be rooted with a custom image to execute arbitrary scripts in the INIT context.
Recommendations
For Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software, consider disabling the ability to install custom images as a temporary workaround until a patch is available. Restrict access to the device's root functionality to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Msm8996
Samsung Mobile Devices