CVE-2019-11341
Summary
| CVE | CVE-2019-11341 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-09 16:15:00 UTC |
| Updated | 2019-11-05 15:02:00 UTC |
| Description | On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic. |
Risk And Classification
Problem Types: CWE-327
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Most Complete Samsung Galaxy Secret Code List!- Dr.Fone | MISC | drfone.wondershare.com | Third Party Advisory |
| Elliot Alderson on Twitter: "THREAD: If you have a @SamsungMobile phones, whatever your phone model, an attacker with a physical access to your phone can capture your network traffic without your consent. Let me show you ⬇️⬇️⬇️… https://t.co/uRHFj6EnVR" | MISC | twitter.com | Exploit, Third Party Advisory |
| Samsung Mobile Security | MISC | security.samsungmobile.com | Not Applicable |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.