// For flags

CVE-2019-5453

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.

Una omisión de la protección de bloqueo en la aplicación de Android Nextcloud anterior a versión 3.3.0 permitía el acceso a los archivos cuando se solicitaba la protección de bloqueo y se cambiaba al proveedor de archivos de Nextcloud.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-04 CVE Reserved
  • 2019-07-30 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
  • CWE-288: Authentication Bypass Using an Alternate Path or Channel
CAPEC
References (1)
URL Tag Source
URL Date SRC
https://hackerone.com/reports/331489 2024-08-04
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nextcloud
Search vendor "Nextcloud"
Nextcloud
Search vendor "Nextcloud" for product "Nextcloud"
<= 3.2.4
Search vendor "Nextcloud" for product "Nextcloud" and version " <= 3.2.4"
android
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud
Search vendor "Nextcloud" for product "Nextcloud"
3.3.0
Search vendor "Nextcloud" for product "Nextcloud" and version "3.3.0"
rc1, android
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud
Search vendor "Nextcloud" for product "Nextcloud"
3.3.0
Search vendor "Nextcloud" for product "Nextcloud" and version "3.3.0"
rc2, android
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud
Search vendor "Nextcloud" for product "Nextcloud"
3.3.0
Search vendor "Nextcloud" for product "Nextcloud" and version "3.3.0"
rc3, android
Affected