CVE-2019-16242
Summary
| CVE | CVE-2019-16242 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 16:15:00 UTC |
| Updated | 2019-12-10 17:11:00 UTC |
| Description | On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary OS commands as the root user via the application's UI. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Alcatelmobile | Cingular Flip 2 | - | All | All | All |
| Hardware | Alcatelmobile | Cingular Flip 2 | - | All | All | All |
| Operating System | Alcatelmobile | Cingular Flip 2 Firmware | b9huah1 | All | All | All |
| Operating System | Alcatelmobile | Cingular Flip 2 Firmware | b9huah1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.nccgroup.trust/uk/our-research | MISC | www.nccgroup.trust | Third Party Advisory |
| www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-i... | MISC | www.nccgroup.trust | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.