[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-4872Date: (C)2012-02-05   (M)2023-12-22


Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
http://archives.neohapsis.com/archives/bugtraq/2012-02/0002.html
SECUNIA-47837
BID-51790
VU#763355
http://blog.mywarwithentropy.com/2012/02/8021x-password-exploit-on-many-htc.html

CPE    10
cpe:/h:htc:desire_hd:frg83d
cpe:/h:htc:glacier:frg83
cpe:/h:htc:sensation_4g:gri40
cpe:/h:htc:evo_4g:gri40
...
CWE    1
CWE-200

© SecPod Technologies