ID

VAR-201611-0412


TITLE

Multiple mtk platform mobile phone Guangsheng FOTA service has system privilege elevation vulnerability (Succubus vulnerability)

Trust: 0.6

sources: CNVD: CNVD-2016-11347

DESCRIPTION

Shanghai Guangsheng Information Technology Co., Ltd. is a leading global provider of terminal management cloud platforms. FOTA (Wireless Upgrade) provides professional wireless upgrade solutions for IoT devices (smart cars, wearables, homes, VR, etc.). A number of mtk platform mobile phone Guangsheng FOTA services have system privilege elevation vulnerabilities. Because the mobile phone using the Guangsheng FOTA service has a vulnerability in the system app of a certain binding service, it is possible to execute commands with system permissions. An attacker could exploit the vulnerability to elevate permissions to system permissions.

Trust: 0.6

sources: CNVD: CNVD-2016-11347

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-11347

AFFECTED PRODUCTS

vendor:guangsheng informationmodel:fota servicescope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-11347

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-11347
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-11347
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:N/C:C/I:P/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 9.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-11347

PATCH

title:Multiple mtk platform mobile phone Guangsheng FOTA service has a system permission elevation vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/84127

Trust: 0.6

sources: CNVD: CNVD-2016-11347

EXTERNAL IDS

db:CNVDid:CNVD-2016-11347

Trust: 0.6

sources: CNVD: CNVD-2016-11347

SOURCES

db:CNVDid:CNVD-2016-11347

LAST UPDATE DATE

2022-05-04T09:57:01.297000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-11347date:2016-11-24T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-11347date:2016-11-21T00:00:00