PT-2024-29682 · Unknown · Smart-Tab Android App
Shuto Imai
·
Published
2024-09-30
·
Updated
2024-09-30
·
CVE-2024-41999
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Smart-tab Android app versions prior to May 2023
Description
The issue concerns an active debug code vulnerability in the Smart-tab Android app. If exploited, an attacker with physical access to the device may use the debug function to access OS functions, escalate privileges, change device settings, or spoof devices in other rooms.
Recommendations
For versions prior to May 2023, as a temporary workaround, consider disabling the debug function until a patch is available. Restrict physical access to devices to minimize the risk of exploitation. Update the Smart-tab Android app to a version released after April 2023 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart-Tab Android App