Lucene search

K
cve[email protected]CVE-2015-3843
HistoryOct 01, 2015 - 12:59 a.m.

CVE-2015-3843

2015-10-0100:59:23
CWE-264
web.nvd.nist.gov
21
sim toolkit
android
security
vulnerability
telephony
cve-2015-3843

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM commands via an application that sends a crafted Intent, related to com/android/internal/telephony/cat/AppInterface.java, aka internal bug 21697171.

Affected configurations

NVD
Node
googleandroidRangeโ‰ค5.1
CPENameOperatorVersion
google:androidgoogle androidle5.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

Related for CVE-2015-3843