ID

VAR-201703-0429


CVE

CVE-2015-0863


TITLE

GALAXY Apps Vulnerability in which important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2015-007450

DESCRIPTION

GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. Samsung Account is prone to an information-disclosure vulnerability. An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. Samsung Account prior to 1.6.0069 and 2.x prior to 2.1.0069 are vulnerable

Trust: 1.89

sources: NVD: CVE-2015-0863 // JVNDB: JVNDB-2015-007450 // BID: 97207

AFFECTED PRODUCTS

vendor:samsungmodel:account appscope:eqversion: -

Trust: 1.6

vendor:samsungmodel:galaxy appscope:eqversion: -

Trust: 1.6

vendor:samsungmodel:galaxy appsscope:ltversion:14120405.03.012

Trust: 0.8

vendor:samsungmodel:accountscope: - version: -

Trust: 0.8

vendor:samsungmodel:galaxy s5scope:eqversion:0

Trust: 0.3

vendor:samsungmodel:androidscope:eqversion:0

Trust: 0.3

vendor:samsungmodel:accountscope:eqversion:1.6.10

Trust: 0.3

vendor:samsungmodel:accountscope:neversion:2.1.69

Trust: 0.3

vendor:samsungmodel:accountscope:neversion:1.6.69

Trust: 0.3

sources: BID: 97207 // JVNDB: JVNDB-2015-007450 // CNNVD: CNNVD-201703-1209 // NVD: CVE-2015-0863

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0863
value: HIGH

Trust: 1.0

NVD: CVE-2015-0863
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201703-1209
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2015-0863
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2015-0863
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: JVNDB: JVNDB-2015-007450 // CNNVD: CNNVD-201703-1209 // NVD: CVE-2015-0863

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.8

sources: JVNDB: JVNDB-2015-007450 // NVD: CVE-2015-0863

THREAT TYPE

network

Trust: 0.3

sources: BID: 97207

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201703-1209

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-007450

PATCH

title:トップページurl:http://www.galaxymobile.jp/

Trust: 0.8

title:Samsung GALAXY Apps Fixes for permission permissions and access control vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74772

Trust: 0.6

sources: JVNDB: JVNDB-2015-007450 // CNNVD: CNNVD-201703-1209

EXTERNAL IDS

db:NVDid:CVE-2015-0863

Trust: 2.7

db:JVNDBid:JVNDB-2015-007450

Trust: 0.8

db:CNNVDid:CNNVD-201703-1209

Trust: 0.6

db:BIDid:97207

Trust: 0.3

sources: BID: 97207 // JVNDB: JVNDB-2015-007450 // CNNVD: CNNVD-201703-1209 // NVD: CVE-2015-0863

REFERENCES

url:https://www.nowsecure.com/blog/2015/01/26/samsung-account-and-galaxy-apps-technical-breakdown-cve-2015-0863-and-cve-2015-0864/

Trust: 2.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0863

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-0863

Trust: 0.8

url:http://www.samsung.com/

Trust: 0.3

sources: BID: 97207 // JVNDB: JVNDB-2015-007450 // NVD: CVE-2015-0863

CREDITS

Ryan Welton and Jake Van Dyke.

Trust: 0.3

sources: BID: 97207

SOURCES

db:BIDid:97207
db:JVNDBid:JVNDB-2015-007450
db:CNNVDid:CNNVD-201703-1209
db:NVDid:CVE-2015-0863

LAST UPDATE DATE

2024-11-23T22:13:09.805000+00:00


SOURCES UPDATE DATE

db:BIDid:97207date:2017-04-04T00:02:00
db:JVNDBid:JVNDB-2015-007450date:2017-05-01T00:00:00
db:CNNVDid:CNNVD-201703-1209date:2017-09-29T00:00:00
db:NVDid:CVE-2015-0863date:2024-11-21T02:23:52.663

SOURCES RELEASE DATE

db:BIDid:97207date:2017-03-27T00:00:00
db:JVNDBid:JVNDB-2015-007450date:2017-05-01T00:00:00
db:CNNVDid:CNNVD-201703-1209date:2017-03-27T00:00:00
db:NVDid:CVE-2015-0863date:2017-03-27T17:59:00.163