CVE-2020-11723
Summary
| CVE | CVE-2020-11723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-14 20:15:00 UTC |
| Updated | 2020-04-22 16:59:00 UTC |
| Description | Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cellebrite | Ufed | - | All | All | All |
| Hardware | Cellebrite | Ufed | - | All | All | All |
| Operating System | Cellebrite | Ufed Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cellebrite UFED 7.29 Hardcoded ADB Authentication Keys ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| UFED and Cellebrite Responder 7.30 provides new support for smartphones with Huawei KIRIN processor - Cellebrite | MISC | www.cellebrite.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.