// For flags

CVE-2018-14825

 

Severity Score

5.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running Android OS 6.0, CT50 running Android OS 4.4, D75e running Android OS 4.4, CN51 running Android OS 6.0, EDA50k running Android 4.4, EDA50 running Android OS 7.1, EDA50k running Android OS 7.1, EDA70 running Android OS 7.1, EDA60k running Android OS 7.1, and EDA51 running Android OS 8.1), a skilled attacker with advanced knowledge of the target system could exploit this vulnerability by creating an application that would successfully bind to the service and gain elevated system privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.

En Honeywell Mobile Computers (CT60 con Android OS 7.1, CN80 con Android OS 7.1, CT40 con Android OS 7.1, CK75 con Android OS 6.0, CN75 con Android OS 6.0, CN75e con Android OS 6.0, CT50 con Android OS 6.0, D75e con Android OS 6.0, CT50 con Android OS 4.4, D75e con Android OS 4.4, CN51 con Android OS 6.0, EDA50k con Android 4.4, EDA50 con Android OS 7.1, EDA50k con Android OS 7.1, EDA70 con Android OS 7.1, EDA60k con Android OS 7.1 y EDA51 con Android OS 8.1), un atacante habilidoso con conocimientos avanzados del sistema objetivo podría explotar esta vulnerabilidad creando una aplicación que se enlazaría exitosamente al servicio y obtendría privilegios elevados en el sistema. Esto podría permitir que el atacante obtenga acceso a las pulsaciones de teclas, contraseñas, información personal identificable, fotografías, emails o documentos críticos para una empresa.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-08-01 CVE Reserved
  • 2018-09-24 CVE Published
  • 2023-09-18 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
  • CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Honeywell
Search vendor "Honeywell"
Cn80
Search vendor "Honeywell" for product "Cn80"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Ct40
Search vendor "Honeywell" for product "Ct40"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Ct60
Search vendor "Honeywell" for product "Ct60"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Eda50
Search vendor "Honeywell" for product "Eda50"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Eda50k
Search vendor "Honeywell" for product "Eda50k"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Eda60k
Search vendor "Honeywell" for product "Eda60k"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Eda70
Search vendor "Honeywell" for product "Eda70"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
7.1.0
Search vendor "Google" for product "Android" and version "7.1.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Ck75
Search vendor "Honeywell" for product "Ck75"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Cn51
Search vendor "Honeywell" for product "Cn51"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Cn75
Search vendor "Honeywell" for product "Cn75"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Cn75e
Search vendor "Honeywell" for product "Cn75e"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
D75e
Search vendor "Honeywell" for product "D75e"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Ct50
Search vendor "Honeywell" for product "Ct50"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4
Search vendor "Google" for product "Android" and version "4.4"
-
Safe
Honeywell
Search vendor "Honeywell"
Ct50
Search vendor "Honeywell" for product "Ct50"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
D75e
Search vendor "Honeywell" for product "D75e"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4
Search vendor "Google" for product "Android" and version "4.4"
-
Safe
Honeywell
Search vendor "Honeywell"
D75e
Search vendor "Honeywell" for product "D75e"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
6.0
Search vendor "Google" for product "Android" and version "6.0"
-
Safe
Honeywell
Search vendor "Honeywell"
Eda50k
Search vendor "Honeywell" for product "Eda50k"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4
Search vendor "Google" for product "Android" and version "4.4"
-
Safe
Honeywell
Search vendor "Honeywell"
Eda51
Search vendor "Honeywell" for product "Eda51"
--
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
8.1
Search vendor "Google" for product "Android" and version "8.1"
-
Safe