CVE-2012-2217
Summary
| CVE | CVE-2012-2217 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-05-01 14:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Htc | Evo 3d | All | All | All | All |
| Hardware | Htc | Evo 3d | gri40 | All | All | All |
| Application | Htc | Evo 3d Software | 1.11.651.3 | All | All | All |
| Application | Htc | Evo 3d Software | 1.13.651.7 | All | All | All |
| Application | Htc | Evo 3d Software | 2.08.651.2 | All | All | All |
| Application | Htc | Evo 3d Software | All | All | All | All |
| Hardware | Htc | Evo 4g | - | All | All | All |
| Hardware | Htc | Evo 4g | gri40 | All | All | All |
| Application | Htc | Evo 4g Software | 1.32.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 1.47.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 3.26.651.6 | All | All | All |
| Application | Htc | Evo 4g Software | 3.29.651.5 | All | All | All |
| Application | Htc | Evo 4g Software | 3.30.651.2 | All | All | All |
| Application | Htc | Evo 4g Software | 3.30.651.3 | All | All | All |
| Application | Htc | Evo 4g Software | 3.70.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 4.22.651.2 | All | All | All |
| Application | Htc | Evo 4g Software | 4.24.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 4.53.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | All | All | All | All |
| Hardware | Htc | Evo Design 4g | - | All | All | All |
| Application | Htc | Evo Design 4g Software | 1.19.651.0 | All | All | All |
| Application | Htc | Evo Design 4g Software | All | All | All | All |
| Hardware | Htc | Evo View 4g | - | All | All | All |
| Application | Htc | Evo View 4g Software | 1.22.651.1 | All | All | All |
| Application | Htc | Evo View 4g Software | All | All | All | All |
| Hardware | Htc | Hero | - | All | All | All |
| Application | Htc | Hero Software | 1.29.651.1 | All | All | All |
| Application | Htc | Hero Software | 1.56.651.2 | All | All | All |
| Application | Htc | Hero Software | 2.27.651.5 | All | All | All |
| Application | Htc | Hero Software | 2.27.651.6 | All | All | All |
| Application | Htc | Hero Software | 2.31.651.7 | All | All | All |
| Application | Htc | Hero Software | 2.32.651.2 | All | All | All |
| Hardware | Htc | Shift 4g | - | All | All | All |
| Application | Htc | Shift 4g Software | 1.17.651.1 | All | All | All |
| Application | Htc | Shift 4g Software | 2.75.651.4 | All | All | All |
| Application | Htc | Shift 4g Software | 2.75.651.5 | All | All | All |
| Application | Htc | Shift 4g Software | All | All | All | All |
| Hardware | Htc | Vivid | - | All | All | All |
| Application | Htc | Vivid Software | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VSR Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.vsecurity.com | |
| Multiple HTC Devices CVE-2012-2217 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.