ID

VAR-201703-0430


CVE

CVE-2015-0864


TITLE

Samsung Account Vulnerability in which important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2015-007451

DESCRIPTION

Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. Samsung Account is prone to an information-disclosure vulnerability. An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. Samsung Account prior to 1.6.0069 and 2.x prior to 2.1.0069 are vulnerable

Trust: 1.98

sources: NVD: CVE-2015-0864 // JVNDB: JVNDB-2015-007451 // BID: 97207 // VULMON: CVE-2015-0864

AFFECTED PRODUCTS

vendor:samsungmodel:account appscope:eqversion: -

Trust: 1.6

vendor:samsungmodel:galaxy appscope:eqversion: -

Trust: 1.6

vendor:samsungmodel:galaxy appsscope: - version: -

Trust: 0.8

vendor:samsungmodel:accountscope:eqversion:2.1.0069

Trust: 0.8

vendor:samsungmodel:accountscope:ltversion:2.x

Trust: 0.8

vendor:samsungmodel:galaxy s5scope:eqversion:0

Trust: 0.3

vendor:samsungmodel:androidscope:eqversion:0

Trust: 0.3

vendor:samsungmodel:accountscope:eqversion:1.6.10

Trust: 0.3

vendor:samsungmodel:accountscope:neversion:2.1.69

Trust: 0.3

vendor:samsungmodel:accountscope:neversion:1.6.69

Trust: 0.3

sources: BID: 97207 // JVNDB: JVNDB-2015-007451 // CNNVD: CNNVD-201703-1208 // NVD: CVE-2015-0864

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0864
value: HIGH

Trust: 1.0

NVD: CVE-2015-0864
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201703-1208
value: HIGH

Trust: 0.6

VULMON: CVE-2015-0864
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0864
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2015-0864
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULMON: CVE-2015-0864 // JVNDB: JVNDB-2015-007451 // CNNVD: CNNVD-201703-1208 // NVD: CVE-2015-0864

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.8

sources: JVNDB: JVNDB-2015-007451 // NVD: CVE-2015-0864

THREAT TYPE

network

Trust: 0.3

sources: BID: 97207

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201703-1208

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-007451

PATCH

title:トップページurl:http://www.galaxymobile.jp/

Trust: 0.8

title:Samsung Account Fixes for permission permissions and access control vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74771

Trust: 0.6

sources: JVNDB: JVNDB-2015-007451 // CNNVD: CNNVD-201703-1208

EXTERNAL IDS

db:NVDid:CVE-2015-0864

Trust: 2.8

db:BIDid:97207

Trust: 1.4

db:JVNDBid:JVNDB-2015-007451

Trust: 0.8

db:CNNVDid:CNNVD-201703-1208

Trust: 0.6

db:VULMONid:CVE-2015-0864

Trust: 0.1

sources: VULMON: CVE-2015-0864 // BID: 97207 // JVNDB: JVNDB-2015-007451 // CNNVD: CNNVD-201703-1208 // NVD: CVE-2015-0864

REFERENCES

url:https://www.nowsecure.com/blog/2015/01/26/samsung-account-and-galaxy-apps-technical-breakdown-cve-2015-0863-and-cve-2015-0864/

Trust: 2.8

url:http://www.securityfocus.com/bid/97207

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0864

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-0864

Trust: 0.8

url:http://www.samsung.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/264.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2015-0864 // BID: 97207 // JVNDB: JVNDB-2015-007451 // CNNVD: CNNVD-201703-1208 // NVD: CVE-2015-0864

CREDITS

Ryan Welton and Jake Van Dyke.

Trust: 0.3

sources: BID: 97207

SOURCES

db:VULMONid:CVE-2015-0864
db:BIDid:97207
db:JVNDBid:JVNDB-2015-007451
db:CNNVDid:CNNVD-201703-1208
db:NVDid:CVE-2015-0864

LAST UPDATE DATE

2024-11-23T22:13:09.775000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2015-0864date:2017-04-04T00:00:00
db:BIDid:97207date:2017-04-04T00:02:00
db:JVNDBid:JVNDB-2015-007451date:2017-05-01T00:00:00
db:CNNVDid:CNNVD-201703-1208date:2017-09-29T00:00:00
db:NVDid:CVE-2015-0864date:2024-11-21T02:23:52.810

SOURCES RELEASE DATE

db:VULMONid:CVE-2015-0864date:2017-03-27T00:00:00
db:BIDid:97207date:2017-03-27T00:00:00
db:JVNDBid:JVNDB-2015-007451date:2017-05-01T00:00:00
db:CNNVDid:CNNVD-201703-1208date:2017-03-27T00:00:00
db:NVDid:CVE-2015-0864date:2017-03-27T17:59:00.227