Lucene search

K
cve[email protected]CVE-2015-6606
HistoryOct 06, 2015 - 5:59 p.m.

CVE-2015-6606

2015-10-0617:59:25
CWE-264
web.nvd.nist.gov
18
cve-2015-6606
secure element evaluation kit
seek
smartcard api
android
privilege escalation
crafted application
signature
nvd
22301786

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.3%

The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.

Affected configurations

NVD
Node
googleandroidRange5.1
CPENameOperatorVersion
google:androidgoogle androidle5.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.3%