Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2018-12446

CVE-2018-12446, sévérité low (CVSS 3.6) : 1 app suivie concernée, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
3.6

Échelle NVD

Exploitation
0.3 %

EPSS, prédiction à 30 jours

Apps suivies
1
Encore exposées
0

EN An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred

Vecteur d'attaque : Local Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS 0.28% exploit très peu probable percentile 21.1%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Dropbox Android com.dropbox.android
    Affecté - Corrigé - Dernière suivie 490.2.2 indéterminé
Configurations CPE vulnérables (1)
Vendor Produit Versions
dropbox dropbox
Android
-
Voir sur NVD ↗