PT-2020-9807 · Dten+2 · Dten D7+3

Published

2020-01-06

·

Updated

2020-08-24

·

CVE-2019-16273

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DTEN D5 and D7 versions prior to 1.3.4
Description The issue allows unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. This also provides a covert ability to capture screen data from the Zoom Client on Windows by executing commands on the Android OS.
Recommendations For DTEN D5 and D7 versions prior to 1.3.4, update to version 1.3.4 or later to resolve the issue. As a temporary workaround, consider disabling the Android Debug Bridge (adb) until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-16273

Affected Products

Android Debug Bridge
Dten D5
Dten D7
Zoom Client