ID

VAR-201812-0111


CVE

CVE-2018-14992


TITLE

ASUS ZenFone 3 Max Android Vulnerabilities related to security functions in devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-014561

DESCRIPTION

The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed platform app with a package name of com.asus.dm (versionCode=1510500200, versionName=1.5.0.40_171122) has an exposed interface in an exported service named com.asus.dm.installer.DMInstallerService that allows any app co-located on the device to use its capabilities to download an arbitrary app over the internet and install it. Any app on the device can send an intent with specific embedded data that will cause the com.asus.dm app to programmatically download and install the app. For the app to be downloaded and installed, certain data needs to be provided: download URL, package name, version name from the app's AndroidManifest.xml file, and the MD5 hash of the app. Moreover, any app that is installed using this method can also be programmatically uninstalled using the same unprotected component named com.asus.dm.installer.DMInstallerService. ASUS ZenFone 3 Max Android The device contains vulnerabilities related to security functions.Information may be tampered with. Attackers can use this vulnerability to download and install any application via the Internet

Trust: 2.25

sources: NVD: CVE-2018-14992 // JVNDB: JVNDB-2018-014561 // CNVD: CNVD-2020-22297 // VULHUB: VHN-125207

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-22297

AFFECTED PRODUCTS

vendor:asusmodel:zenfone 3 maxscope:eqversion:1.5.0.40

Trust: 1.0

vendor:asustek computermodel:zenfone 3 maxscope:eqversion:1.5.0.40_171122

Trust: 0.8

vendor:asusmodel:zenfone maxscope:eqversion:3

Trust: 0.6

sources: CNVD: CNVD-2020-22297 // JVNDB: JVNDB-2018-014561 // NVD: CVE-2018-14992

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-14992
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-14992
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-22297
value: LOW

Trust: 0.6

CNNVD: CNNVD-201812-1252
value: MEDIUM

Trust: 0.6

VULHUB: VHN-125207
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2018-14992
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-22297
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-125207
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-14992
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2020-22297 // VULHUB: VHN-125207 // JVNDB: JVNDB-2018-014561 // CNNVD: CNNVD-201812-1252 // NVD: CVE-2018-14992

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-254

Trust: 0.9

sources: VULHUB: VHN-125207 // JVNDB: JVNDB-2018-014561 // NVD: CVE-2018-14992

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201812-1252

TYPE

security feature problem

Trust: 0.6

sources: CNNVD: CNNVD-201812-1252

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014561

PATCH

title:Top Pageurl:https://www.asustor.com/

Trust: 0.8

sources: JVNDB: JVNDB-2018-014561

EXTERNAL IDS

db:NVDid:CVE-2018-14992

Trust: 3.1

db:JVNDBid:JVNDB-2018-014561

Trust: 0.8

db:CNVDid:CNVD-2020-22297

Trust: 0.7

db:CNNVDid:CNNVD-201812-1252

Trust: 0.7

db:VULHUBid:VHN-125207

Trust: 0.1

sources: CNVD: CNVD-2020-22297 // VULHUB: VHN-125207 // JVNDB: JVNDB-2018-014561 // CNNVD: CNNVD-201812-1252 // NVD: CVE-2018-14992

REFERENCES

url:https://www.kryptowire.com/portal/wp-content/uploads/2018/12/defcon-26-johnson-and-stavrou-vulnerable-out-of-the-box-an-eval-of-android-carrier-devices-wp-updated.pdf

Trust: 2.5

url:https://www.kryptowire.com/portal/android-firmware-defcon-2018/

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-14992

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-14992

Trust: 0.8

url:https://www.kryptowire.com/android-firmware-defcon-2018/

Trust: 0.8

sources: CNVD: CNVD-2020-22297 // VULHUB: VHN-125207 // JVNDB: JVNDB-2018-014561 // CNNVD: CNNVD-201812-1252 // NVD: CVE-2018-14992

SOURCES

db:CNVDid:CNVD-2020-22297
db:VULHUBid:VHN-125207
db:JVNDBid:JVNDB-2018-014561
db:CNNVDid:CNNVD-201812-1252
db:NVDid:CVE-2018-14992

LAST UPDATE DATE

2024-11-23T23:11:57.408000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-22297date:2020-04-11T00:00:00
db:VULHUBid:VHN-125207date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2018-014561date:2019-03-27T00:00:00
db:CNNVDid:CNNVD-201812-1252date:2020-10-22T00:00:00
db:NVDid:CVE-2018-14992date:2024-11-21T03:50:16.570

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-22297date:2020-04-11T00:00:00
db:VULHUBid:VHN-125207date:2018-12-28T00:00:00
db:JVNDBid:JVNDB-2018-014561date:2019-03-27T00:00:00
db:CNNVDid:CNNVD-201812-1252date:2018-12-29T00:00:00
db:NVDid:CVE-2018-14992date:2018-12-28T21:29:00.603