ID

VAR-201410-1185


CVE

CVE-2014-8346


TITLE

Samsung Mobile device Remote Controls Service disruption in functionality (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-005070

DESCRIPTION

The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic. Remote Controls feature on Samsung mobile devices is a remote control feature used by Samsung in South Korea for Samsung mobile devices. Mobile is prone to a denial-of-service vulnerability

Trust: 2.43

sources: NVD: CVE-2014-8346 // JVNDB: JVNDB-2014-005070 // CNVD: CNVD-2014-07561 // BID: 77794

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-07561

AFFECTED PRODUCTS

vendor:samsungmodel:findmymobilescope:eqversion: -

Trust: 1.9

vendor:samsungmodel:mobilescope:eqversion: -

Trust: 1.3

vendor:samsungmodel:find my mobilescope: - version: -

Trust: 0.8

vendor:samsungmodel:mobilescope: - version: -

Trust: 0.8

vendor:samsungmodel:mmobilescope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-07561 // BID: 77794 // JVNDB: JVNDB-2014-005070 // CNNVD: CNNVD-201410-1292 // NVD: CVE-2014-8346

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8346
value: HIGH

Trust: 1.0

NVD: CVE-2014-8346
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-07561
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201410-1292
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2014-8346
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-07561
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-07561 // JVNDB: JVNDB-2014-005070 // CNNVD: CNNVD-201410-1292 // NVD: CVE-2014-8346

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.8

sources: JVNDB: JVNDB-2014-005070 // NVD: CVE-2014-8346

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-1292

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-201410-1292

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-005070

PATCH

title:Top Pageurl:http://content.samsung.com/jp/main.do

Trust: 0.8

sources: JVNDB: JVNDB-2014-005070

EXTERNAL IDS

db:NVDid:CVE-2014-8346

Trust: 3.3

db:JVNDBid:JVNDB-2014-005070

Trust: 0.8

db:CNVDid:CNVD-2014-07561

Trust: 0.6

db:CNNVDid:CNNVD-201410-1292

Trust: 0.6

db:BIDid:77794

Trust: 0.3

sources: CNVD: CNVD-2014-07561 // BID: 77794 // JVNDB: JVNDB-2014-005070 // CNNVD: CNNVD-201410-1292 // NVD: CVE-2014-8346

REFERENCES

url:https://www.youtube.com/watch?v=q3adkpoejyi

Trust: 3.3

url:https://www.youtube.com/watch?v=yufuoyqodoy

Trust: 2.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8346

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-8346

Trust: 0.8

sources: CNVD: CNVD-2014-07561 // BID: 77794 // JVNDB: JVNDB-2014-005070 // CNNVD: CNNVD-201410-1292 // NVD: CVE-2014-8346

CREDITS

Unknown

Trust: 0.3

sources: BID: 77794

SOURCES

db:CNVDid:CNVD-2014-07561
db:BIDid:77794
db:JVNDBid:JVNDB-2014-005070
db:CNNVDid:CNNVD-201410-1292
db:NVDid:CVE-2014-8346

LAST UPDATE DATE

2025-04-13T23:31:37.131000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-07561date:2014-10-30T00:00:00
db:BIDid:77794date:2014-10-24T00:00:00
db:JVNDBid:JVNDB-2014-005070date:2014-10-28T00:00:00
db:CNNVDid:CNNVD-201410-1292date:2014-10-28T00:00:00
db:NVDid:CVE-2014-8346date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-07561date:2014-10-30T00:00:00
db:BIDid:77794date:2014-10-24T00:00:00
db:JVNDBid:JVNDB-2014-005070date:2014-10-28T00:00:00
db:CNNVDid:CNNVD-201410-1292date:2014-10-28T00:00:00
db:NVDid:CVE-2014-8346date:2014-10-24T10:55:05.133