QID 630858

Date Published: 2023-03-03

QID 630858: Nextcloud Talk For Android Improper Access Control Vulnerability

Talk-Android enables users to have video and audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the users Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the targets device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Low - 2.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to CVE-2023-22473 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630858

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-22473 iOS URL Logo nvd.nist.gov/vuln/detail/CVE-2023-22473