CVE-2019-16401
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband: I9300XXUGNA8), and Samsung Galaxy Note 2 (Android version: 4.3, Build Number: JSS15J.I9300XUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband: N7100DDUFND1) devices allow injection of AT+CIMI and AT+CGSN over Bluetooth, leaking sensitive information such as IMSI, IMEI, call status, call setup stage, internet service status, signal strength, current roaming status, battery level, and call held status.
Los dispositivos Samsung Galaxy S8 plus (versión de Android: 8.0.0, Número de Compilación: R16NW.G955USQU5CRG3, Suplidor de Banda Base: Qualcomm Snapdragon 835, Banda Base: G955USQU5CRG3), Samsung Galaxy S3 (versión de Android: 4.3, Número de Compilación: JSS15J.I9300XXUGND5, Suplidor de Banda Base: Samsung Exynos 4412, Banda Base: I9300XXUGNA8) y Samsung Galaxy Note 2 (versión de Android: 4.3, Número de Compilación: JSS15J.I9300XUGND5, Suplidor de Banda Base: Samsung Exynos 4412, Banda Base: N7100DDUFND1), permiten la inyección de AT+CIMI y AT+CGSN mediante Bluetooth, una filtrado de información confidencial, como IMSI, IMEI, estado de la llamada, etapa de configuración de la llamada, estado del servicio de Internet, intensidad de la señal, estado de roaming actual, nivel de batería y estado de llamada retenida.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-18 CVE Reserved
- 2019-11-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.openconf.org/acsac2019/modules/request.php?module=oc_program&action=summary.php&id=210 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Samsung Search vendor "Samsung" | Galaxy S8 Plus Firmware Search vendor "Samsung" for product "Galaxy S8 Plus Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy S8 Plus Search vendor "Samsung" for product "Galaxy S8 Plus" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Galaxy S3 Firmware Search vendor "Samsung" for product "Galaxy S3 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy S3 Search vendor "Samsung" for product "Galaxy S3" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Galaxy Note 2 Firmware Search vendor "Samsung" for product "Galaxy Note 2 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy Note 2 Search vendor "Samsung" for product "Galaxy Note 2" | - | - |
Safe
|