Lucene search

K
cve[email protected]CVE-2011-4872
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-4872

2022-10-0316:15:14
CWE-200
web.nvd.nist.gov
30
cve-2011-4872
htc
android devices
wi-fi
credential leakage
remote attack
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.9%

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

Affected configurations

NVD
Node
htcdesire_hdMatchfrg83d
OR
htcdesire_hdMatchgri40
OR
htcdesire_sMatchgri40
OR
htcdroid_incredibleMatchfrf91
OR
htcevo_3dMatchgri40
OR
htcevo_4gMatchgri40
OR
htcglacierMatchfrg83
OR
htcsensation_4gMatchgri40
OR
htcsensation_z710eMatchgri40
OR
htcthunderbolt_4gMatchfrg83d

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.9%

Related for CVE-2011-4872