Lucene search

K
nvd[email protected]NVD:CVE-2023-28153
HistoryMay 29, 2023 - 1:15 a.m.

CVE-2023-28153

2023-05-2901:15:11
web.nvd.nist.gov
2
vulnerability
kiddoware
android
parental control
permission bypass
security issue
cve-2023-28153

CVSS3

6.4

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

29.1%

An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child can remove all restrictions temporarily without the parents noticing by rebooting into Android Safe Mode and disabling the “Display over other apps” permission.

Affected configurations

Nvd
Node
kiddowarekiddowareRange<3.8.50android
VendorProductVersionCPE
kiddowarekiddoware*cpe:2.3:a:kiddoware:kiddoware:*:*:*:*:*:android:*:*

CVSS3

6.4

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

29.1%

Related for NVD:CVE-2023-28153