ZTE Score M 'sync_agent ' Hardcoded Password Security Bypass Vulnerability
BID:54079
Info
ZTE Score M 'sync_agent ' Hardcoded Password Security Bypass Vulnerability
| Bugtraq ID: | 54079 |
| Class: | Design Error |
| CVE: |
CVE-2012-2949 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2012 12:00AM |
| Updated: | Mar 19 2015 08:12AM |
| Credit: | Unknown |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ZTE Score M 'sync_agent ' Hardcoded Password Security Bypass Vulnerability
ZTE Score M is prone to a security-bypass vulnerability caused by a hard-coded password.
An attacker can exploit this issue by enticing an unsuspecting victim to install a malicious application on the device.
Successful attacks can allow a remote attacker to gain unauthorized root access to the vulnerable device.
ZTE Score M is prone to a security-bypass vulnerability caused by a hard-coded password.
An attacker can exploit this issue by enticing an unsuspecting victim to install a malicious application on the device.
Successful attacks can allow a remote attacker to gain unauthorized root access to the vulnerable device.
Exploit / POC
ZTE Score M 'sync_agent ' Hardcoded Password Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at:[email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at:[email protected].
Solution / Fix
ZTE Score M 'sync_agent ' Hardcoded Password Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ZTE Score M 'sync_agent ' Hardcoded Password Security Bypass Vulnerability
References:
References: