CVE-2021-25442
https://notcve.org/view.php?id=CVE-2021-25442
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication. Una vulnerabilidad de administración de políticas MDM inapropiada en el módulo KME anteriores a versión 1.39 de KCS, permite a usuarios de MDM omitir la autenticación de Knox Manage • https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=7 • CWE-269: Improper Privilege Management CWE-287: Improper Authentication •
CVE-2019-6744 – Samsung Knox Secure Folder Lock Screen Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2019-6744
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. • https://security.samsungmobile.com/securityUpdate.smsb https://www.zerodayinitiative.com/advisories/ZDI-19-515 • CWE-284: Improper Access Control CWE-287: Improper Authentication •
CVE-2017-10963
https://notcve.org/view.php?id=CVE-2017-10963
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence. This installed application can further leak information stored inside the Knox container to the outside world. En Knox SDS IAM (Identity Access Management) y EMM (Enterprise Mobility Management) 16.11 en dispositivos móviles de Samsung, un atacante Man-in-the-Middle (MitM) puede instalar cualquier aplicación en el contenedor de Knox (sin que el usuario lo sepa) inspeccionando el tráfico de red de un servidor Samsung e inyectando contenido en un punto específico de la secuencia de actualización. La aplicación instalada puede filtrar información almacenada en el contenedor de Knox al exterior. • https://gist.github.com/e96e02/12ce905e3b724954273dd7d543a968f1 https://www.lgsinnovations.com/lgs-innovations-discovers-samsung-mobile-product-security-vulnerability • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2016-1920
https://notcve.org/view.php?id=CVE-2016-1920
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service. Samsung KNOX 1.0.0 utiliza el certificado compartido en Android, lo que permite a usuarios locales llevar a cabo ataques man-in-the-middle como se demuestra instalando un certificado y ejecutando un servicio VPN. • http://www.securityfocus.com/archive/1/537318/100/0/threaded http://www.securityfocus.com/archive/1/537339/100/0/threaded • CWE-284: Improper Access Control •
CVE-2016-3996 – KNOX 2.3 Clipboard Data Disclosure
https://notcve.org/view.php?id=CVE-2016-3996
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application. ClipboardDataMgr en Samsung KNOX 1.0.0 y 2.3.0 no verifica adecuadamente a quien llama, lo que permite a usuarios locales leer datos de portapapeles de KNOX a través de una aplicación manipulada. KNOX versions 1.0 through 2.3 on Android suffer from a clipboard data disclosure vulnerability. • http://packetstormsecurity.com/files/136710/KNOX-2.3-Clipboard-Data-Disclosure.html http://www.securityfocus.com/archive/1/538113/100/0/threaded • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •