Lucene search

K
cveGitHub_MCVE-2022-41926
HistoryNov 25, 2022 - 7:15 p.m.

CVE-2022-41926

2022-11-2519:15:11
CWE-200
CWE-732
GitHub_M
web.nvd.nist.gov
36
10
cve-2022-41926
nextcloud talk
android
communication monitoring
upgrade
security issue

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.1%

Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that the Nextcloud Talk Android is upgraded to 14.1.0. There are no known workarounds for this issue.

Affected configurations

Nvd
Vulners
Node
nextcloudtalkRange<14.1.0android
VendorProductVersionCPE
nextcloudtalk*cpe:2.3:a:nextcloud:talk:*:*:*:*:*:android:*:*

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": "< 14.1.0",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.1%

Related for CVE-2022-41926