Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 | Vendor Advisory |
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
21 Nov 2024, 08:22
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory |
12 Dec 2023, 21:22
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CWE | CWE-319 | |
CPE | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:* cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
|
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory |
05 Dec 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-05 03:15
Updated : 2024-11-21 08:22
NVD link : CVE-2023-42579
Mitre link : CVE-2023-42579
CVE.ORG link : CVE-2023-42579
JSON object : View
Products Affected
- android
samsung
- samsung_keyboard
CWE
CWE-319
Cleartext Transmission of Sensitive Information