PT-2024-29682 · Unknown · Smart-Tab Android App

Shuto Imai

·

Published

2024-09-30

·

Updated

2024-09-30

·

CVE-2024-41999

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Smart-tab Android app versions prior to May 2023
Description The issue concerns an active debug code vulnerability in the Smart-tab Android app. If exploited, an attacker with physical access to the device may use the debug function to access OS functions, escalate privileges, change device settings, or spoof devices in other rooms.
Recommendations For versions prior to May 2023, as a temporary workaround, consider disabling the debug function until a patch is available. Restrict physical access to devices to minimize the risk of exploitation. Update the Smart-tab Android app to a version released after April 2023 to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-41999

Affected Products

Smart-Tab Android App