ID

VAR-201911-0472


CVE

CVE-2019-15403


TITLE

ASUS ZenFone 3s Max Access Control Error Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2020-14731 // CNNVD: CNNVD-201911-908

DESCRIPTION

The Asus ZenFone 3s Max Android device with a build fingerprint of asus/IN_X00G/ASUS_X00G_1:7.0/NRD90M/IN_X00G-14.02.1807.33-20180706:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app. Asus ZenFone 3s Max Android Devices are vulnerable to improper assignment of permissions to critical resources.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. ASUS ZenFone 3s Max is a smartphone from ASUS, Taiwan. ASUS ZenFone 3s Max has an access control error vulnerability. The vulnerability stems from a network system or product that did not properly restrict access to resources from unauthorized roles. An attacker could use this vulnerability to execute commands through an accessible application component

Trust: 2.16

sources: NVD: CVE-2019-15403 // JVNDB: JVNDB-2019-012318 // CNVD: CNVD-2020-14731

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-14731

AFFECTED PRODUCTS

vendor:asusmodel:zenfone 3s maxscope:eqversion: -

Trust: 1.0

vendor:asustek computermodel:zenfone 3s maxscope: - version: -

Trust: 0.8

vendor:asusmodel:zenfone 3s maxscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-14731 // JVNDB: JVNDB-2019-012318 // NVD: CVE-2019-15403

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-15403
value: HIGH

Trust: 1.0

NVD: CVE-2019-15403
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-14731
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201911-908
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-15403
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-14731
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-15403
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2019-15403
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-14731 // JVNDB: JVNDB-2019-012318 // CNNVD: CNNVD-201911-908 // NVD: CVE-2019-15403

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-732

Trust: 0.8

sources: JVNDB: JVNDB-2019-012318 // NVD: CVE-2019-15403

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201911-908

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-201911-908

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-012318

PATCH

title:ZenFone 3 Max (ZC520TL)url:https://www.asus.com/jp/Phone/ZenFone-3-Max-ZC520TL/

Trust: 0.8

sources: JVNDB: JVNDB-2019-012318

EXTERNAL IDS

db:NVDid:CVE-2019-15403

Trust: 3.0

db:JVNDBid:JVNDB-2019-012318

Trust: 0.8

db:CNVDid:CNVD-2020-14731

Trust: 0.6

db:CNNVDid:CNNVD-201911-908

Trust: 0.6

sources: CNVD: CNVD-2020-14731 // JVNDB: JVNDB-2019-012318 // CNNVD: CNNVD-201911-908 // NVD: CVE-2019-15403

REFERENCES

url:https://www.kryptowire.com/android-firmware-2019/

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-15403

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-15403

Trust: 0.8

sources: CNVD: CNVD-2020-14731 // JVNDB: JVNDB-2019-012318 // CNNVD: CNNVD-201911-908 // NVD: CVE-2019-15403

SOURCES

db:CNVDid:CNVD-2020-14731
db:JVNDBid:JVNDB-2019-012318
db:CNNVDid:CNNVD-201911-908
db:NVDid:CVE-2019-15403

LAST UPDATE DATE

2024-11-23T21:59:38.677000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-14731date:2020-03-01T00:00:00
db:JVNDBid:JVNDB-2019-012318date:2019-11-29T00:00:00
db:CNNVDid:CNNVD-201911-908date:2020-08-25T00:00:00
db:NVDid:CVE-2019-15403date:2024-11-21T04:28:38.877

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-14731date:2020-03-01T00:00:00
db:JVNDBid:JVNDB-2019-012318date:2019-11-29T00:00:00
db:CNNVDid:CNNVD-201911-908date:2019-11-14T00:00:00
db:NVDid:CVE-2019-15403date:2019-11-14T17:15:20.023