// For flags

CVE-2015-4640

 

Severity Score

8.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP connection to the skslm.swiftkey.net server, which allows man-in-the-middle attackers to write to language-pack files by modifying an HTTP response. NOTE: CVE-2015-4640 exploitation can be combined with CVE-2015-4641 exploitation for man-in-the-middle code execution.

La implementación de la actualización del paquete de lenguas SwiftKey en los dispositivos Samsung Galaxy S4, S4 Mini, S5, y S6 depende de una conexión HTTP al servidor skslm.swiftkey.net, lo que permite a atacantes man-in-the-middle escribir en ficheros del paquete de lenguas mediante la modificación de una respuesta HTTP. NOTA: La explotación de CVE-2015-4640 puede combinarse con la explotación de CVE-2015-4641 para la ejecución de código man-in-the-middle.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-17 CVE Reserved
  • 2015-06-19 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-254: 7PK - Security Features
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S4
Search vendor "Samsung" for product "Galaxy S4"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S4 Mini
Search vendor "Samsung" for product "Galaxy S4 Mini"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S5
Search vendor "Samsung" for product "Galaxy S5"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S6
Search vendor "Samsung" for product "Galaxy S6"
*-
Safe