// For flags

CVE-2015-4640

 

Severity Score

2.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP connection to the skslm.swiftkey.net server, which allows man-in-the-middle attackers to write to language-pack files by modifying an HTTP response. NOTE: CVE-2015-4640 exploitation can be combined with CVE-2015-4641 exploitation for man-in-the-middle code execution.

La implementación de la actualización del paquete de lenguas SwiftKey en los dispositivos Samsung Galaxy S4, S4 Mini, S5, y S6 depende de una conexión HTTP al servidor skslm.swiftkey.net, lo que permite a atacantes man-in-the-middle escribir en ficheros del paquete de lenguas mediante la modificación de una respuesta HTTP. NOTA: La explotación de CVE-2015-4640 puede combinarse con la explotación de CVE-2015-4641 para la ejecución de código man-in-the-middle.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-17 CVE Reserved
  • 2015-06-19 CVE Published
  • 2024-02-24 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-254: 7PK - Security Features
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S4
Search vendor "Samsung" for product "Galaxy S4"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S4 Mini
Search vendor "Samsung" for product "Galaxy S4 Mini"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S5
Search vendor "Samsung" for product "Galaxy S5"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S6
Search vendor "Samsung" for product "Galaxy S6"
*-
Safe