Lucene search

K
cveMitreCVE-2019-15377
HistoryNov 14, 2019 - 5:15 p.m.

CVE-2019-15377

2019-11-1417:15:18
mitre
web.nvd.nist.gov
19
cve-2019-15377
cherry flare s7
android device
vulnerability
com.mediatek.wfo.impl
nvd
security issue

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

12.6%

The Cherry Flare S7 Android device with a build fingerprint of Cherry_Mobile/Flare_S7_Deluxe/Flare_S7_Deluxe:8.1.0/O11019/1533920920:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

Affected configurations

Nvd
Node
cherrymobileflare_s7Match-
AND
cherrymobileflare_s7_firmwareMatch-
VendorProductVersionCPE
cherrymobileflare_s7-cpe:2.3:h:cherrymobile:flare_s7:-:*:*:*:*:*:*:*
cherrymobileflare_s7_firmware-cpe:2.3:o:cherrymobile:flare_s7_firmware:-:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2019-15377