Vulnérabilité · NVD
CVE-2018-15542
MEDIUM 6.4
EN An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
Vecteur d'attaque : Physique
Aucun privilège requis
Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.34%
exploit très peu probable
percentile 27.0%
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
Configurations CPE vulnérables (1)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| telegram |
telegram Android
|
Android | — | cpe:2.3:a:telegram:telegram:4.8.11:*:*:*:*:android:*:* |