Lucene search

K
cveIcscertCVE-2018-14825
HistorySep 24, 2018 - 8:00 p.m.

CVE-2018-14825

2018-09-2420:00:00
CWE-269
CWE-732
icscert
web.nvd.nist.gov
37
cve-2018-14825
honeywell
mobile computers
android
os
vulnerability
system privileges
exploit
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

5.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

40.8%

On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running Android OS 6.0, CT50 running Android OS 4.4, D75e running Android OS 4.4, CN51 running Android OS 6.0, EDA50k running Android 4.4, EDA50 running Android OS 7.1, EDA50k running Android OS 7.1, EDA70 running Android OS 7.1, EDA60k running Android OS 7.1, and EDA51 running Android OS 8.1), a skilled attacker with advanced knowledge of the target system could exploit this vulnerability by creating an application that would successfully bind to the service and gain elevated system privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.

Affected configurations

Nvd
Node
honeywellcn80Match-
OR
honeywellct40Match-
OR
honeywellct60Match-
OR
honeywelleda50Match-
OR
honeywelleda50kMatch-
OR
honeywelleda60kMatch-
OR
honeywelleda70Match-
AND
googleandroidMatch7.1.0
Node
honeywellck75Match-
OR
honeywellcn51Match-
OR
honeywellcn75Match-
OR
honeywellcn75eMatch-
OR
honeywelld75eMatch-
AND
googleandroidMatch6.0
Node
honeywellct50Match-
OR
honeywelld75eMatch-
AND
googleandroidMatch4.4
OR
googleandroidMatch6.0
Node
honeywelleda50kMatch-
AND
googleandroidMatch4.4
Node
honeywelleda51Match-
AND
googleandroidMatch8.1
VendorProductVersionCPE
honeywellcn80-cpe:2.3:h:honeywell:cn80:-:*:*:*:*:*:*:*
honeywellct40-cpe:2.3:h:honeywell:ct40:-:*:*:*:*:*:*:*
honeywellct60-cpe:2.3:h:honeywell:ct60:-:*:*:*:*:*:*:*
honeywelleda50-cpe:2.3:h:honeywell:eda50:-:*:*:*:*:*:*:*
honeywelleda50k-cpe:2.3:h:honeywell:eda50k:-:*:*:*:*:*:*:*
honeywelleda60k-cpe:2.3:h:honeywell:eda60k:-:*:*:*:*:*:*:*
honeywelleda70-cpe:2.3:h:honeywell:eda70:-:*:*:*:*:*:*:*
googleandroid7.1.0cpe:2.3:o:google:android:7.1.0:*:*:*:*:*:*:*
honeywellck75-cpe:2.3:h:honeywell:ck75:-:*:*:*:*:*:*:*
honeywellcn51-cpe:2.3:h:honeywell:cn51:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CNA Affected

[
  {
    "product": "Mobile Computers",
    "vendor": "Honeywell",
    "versions": [
      {
        "status": "affected",
        "version": "CT60 running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "CN80 running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "CT40 running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "CK75 running Android OS 6.0"
      },
      {
        "status": "affected",
        "version": "CN75 running Android OS 6.0"
      },
      {
        "status": "affected",
        "version": "CN75e running Android OS 6.0"
      },
      {
        "status": "affected",
        "version": "CT50 running Android OS 6.0"
      },
      {
        "status": "affected",
        "version": "D75e running Android OS 6.0"
      },
      {
        "status": "affected",
        "version": "CT50 running Android OS 4.4"
      },
      {
        "status": "affected",
        "version": "D75e running Android OS 4.4"
      },
      {
        "status": "affected",
        "version": "CN51 running Android OS 6.0"
      },
      {
        "status": "affected",
        "version": "EDA50k running Android 4.4"
      },
      {
        "status": "affected",
        "version": "EDA50 running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "EDA50k running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "EDA70 running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "EDA60k running Android OS 7.1"
      },
      {
        "status": "affected",
        "version": "EDA51 running Android OS 8.1"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

5.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

40.8%

Related for CVE-2018-14825