Lucene search

K
cveGitHub_MCVE-2023-22473
HistoryJan 09, 2023 - 3:15 p.m.

CVE-2023-22473

2023-01-0915:15:11
CWE-284
GitHub_M
web.nvd.nist.gov
49
talk-android
nextcloud
android
passcode bypass
security vulnerability
audio calls
video calls
nvd

CVSS3

2.1

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

3.6

Confidence

High

EPSS

0.001

Percentile

26.7%

Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user’s Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target’s device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.

Affected configurations

Nvd
Vulners
Node
nextcloudtalkRange<15.0.2android
VendorProductVersionCPE
nextcloudtalk*cpe:2.3:a:nextcloud:talk:*:*:*:*:*:android:*:*

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": "< 15.0.2",
        "status": "affected"
      }
    ]
  }
]

CVSS3

2.1

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

3.6

Confidence

High

EPSS

0.001

Percentile

26.7%