CVE-2012-2217
Summary
| CVE | CVE-2012-2217 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-05-01 14:55:00 UTC |
| Updated | 2017-12-14 02:29:00 UTC |
| Description | The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Htc | Evo 3d | All | All | All | All |
| Hardware | Htc | Evo 3d | gri40 | All | All | All |
| Hardware | Htc | Evo 3d | All | All | All | All |
| Hardware | Htc | Evo 3d | gri40 | All | All | All |
| Application | Htc | Evo 3d Software | 1.11.651.3 | All | All | All |
| Application | Htc | Evo 3d Software | 1.13.651.7 | All | All | All |
| Application | Htc | Evo 3d Software | 2.08.651.2 | All | All | All |
| Application | Htc | Evo 3d Software | 1.11.651.3 | All | All | All |
| Application | Htc | Evo 3d Software | 1.13.651.7 | All | All | All |
| Application | Htc | Evo 3d Software | 2.08.651.2 | All | All | All |
| Application | Htc | Evo 3d Software | All | All | All | All |
| Hardware | Htc | Evo 4g | - | All | All | All |
| Hardware | Htc | Evo 4g | gri40 | All | All | All |
| Hardware | Htc | Evo 4g | - | All | All | All |
| Hardware | Htc | Evo 4g | gri40 | All | All | All |
| Application | Htc | Evo 4g Software | 1.32.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 1.47.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 3.26.651.6 | All | All | All |
| Application | Htc | Evo 4g Software | 3.29.651.5 | All | All | All |
| Application | Htc | Evo 4g Software | 3.30.651.2 | All | All | All |
| Application | Htc | Evo 4g Software | 3.30.651.3 | All | All | All |
| Application | Htc | Evo 4g Software | 3.70.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 4.22.651.2 | All | All | All |
| Application | Htc | Evo 4g Software | 4.24.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 4.53.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 1.32.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 1.47.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 3.26.651.6 | All | All | All |
| Application | Htc | Evo 4g Software | 3.29.651.5 | All | All | All |
| Application | Htc | Evo 4g Software | 3.30.651.2 | All | All | All |
| Application | Htc | Evo 4g Software | 3.30.651.3 | All | All | All |
| Application | Htc | Evo 4g Software | 3.70.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 4.22.651.2 | All | All | All |
| Application | Htc | Evo 4g Software | 4.24.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | 4.53.651.1 | All | All | All |
| Application | Htc | Evo 4g Software | All | All | All | All |
| Hardware | Htc | Evo Design 4g | - | All | All | All |
| Hardware | Htc | Evo Design 4g | - | All | All | All |
| Application | Htc | Evo Design 4g Software | 1.19.651.0 | All | All | All |
| Application | Htc | Evo Design 4g Software | 1.19.651.0 | All | All | All |
| Application | Htc | Evo Design 4g Software | All | All | All | All |
| Hardware | Htc | Evo View 4g | - | All | All | All |
| Hardware | Htc | Evo View 4g | - | All | All | All |
| Application | Htc | Evo View 4g Software | 1.22.651.1 | All | All | All |
| Application | Htc | Evo View 4g Software | 1.22.651.1 | All | All | All |
| Application | Htc | Evo View 4g Software | All | All | All | All |
| Hardware | Htc | Hero | - | All | All | All |
| Hardware | Htc | Hero | - | All | All | All |
| Application | Htc | Hero Software | 1.29.651.1 | All | All | All |
| Application | Htc | Hero Software | 1.56.651.2 | All | All | All |
| Application | Htc | Hero Software | 2.27.651.5 | All | All | All |
| Application | Htc | Hero Software | 2.27.651.6 | All | All | All |
| Application | Htc | Hero Software | 2.31.651.7 | All | All | All |
| Application | Htc | Hero Software | 2.32.651.2 | All | All | All |
| Application | Htc | Hero Software | 1.29.651.1 | All | All | All |
| Application | Htc | Hero Software | 1.56.651.2 | All | All | All |
| Application | Htc | Hero Software | 2.27.651.5 | All | All | All |
| Application | Htc | Hero Software | 2.27.651.6 | All | All | All |
| Application | Htc | Hero Software | 2.31.651.7 | All | All | All |
| Application | Htc | Hero Software | 2.32.651.2 | All | All | All |
| Hardware | Htc | Shift 4g | - | All | All | All |
| Hardware | Htc | Shift 4g | - | All | All | All |
| Application | Htc | Shift 4g Software | 1.17.651.1 | All | All | All |
| Application | Htc | Shift 4g Software | 2.75.651.4 | All | All | All |
| Application | Htc | Shift 4g Software | 2.75.651.5 | All | All | All |
| Application | Htc | Shift 4g Software | 1.17.651.1 | All | All | All |
| Application | Htc | Shift 4g Software | 2.75.651.4 | All | All | All |
| Application | Htc | Shift 4g Software | 2.75.651.5 | All | All | All |
| Application | Htc | Shift 4g Software | All | All | All | All |
| Hardware | Htc | Vivid | - | All | All | All |
| Hardware | Htc | Vivid | - | All | All | All |
| Application | Htc | Vivid Software | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Multiple HTC Devices CVE-2012-2217 Security Bypass Vulnerability | BID | www.securityfocus.com | |
| VSR Security Advisories | MISC | www.vsecurity.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | BUGTRAQ | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.