ID

VAR-202010-0555


CVE

CVE-2020-26604


TITLE

Samsung  Privilege management vulnerabilities in mobile devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-011935

DESCRIPTION

An issue was discovered in SystemUI on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows an unprivileged process to access contact numbers. The Samsung ID is SVE-2020-18467 (October 2020). This vulnerability is Samsung ID: SVE-2020-18467 It is published as.Information may be obtained. are all products of South Korean Samsung (Samsung). The vulnerability originates in SystemUI

Trust: 2.16

sources: NVD: CVE-2020-26604 // JVNDB: JVNDB-2020-011935 // CNVD: CNVD-2020-65258

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-65258

AFFECTED PRODUCTS

vendor:googlemodel:androidscope:eqversion:8.1

Trust: 1.0

vendor:googlemodel:androidscope:eqversion:9.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion:11.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion:8.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion:10.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion: -

Trust: 0.8

vendor:googlemodel:androidscope:eqversion:o(8.x)

Trust: 0.8

vendor:googlemodel:androidscope:eqversion:p(9.0)

Trust: 0.8

vendor:googlemodel:androidscope:eqversion:q(10.0)

Trust: 0.8

vendor:googlemodel:androidscope:eqversion:r(11.0)

Trust: 0.8

vendor:googlemodel:androidscope: - version: -

Trust: 0.8

vendor:samsungmodel:mobile devices pscope: - version: -

Trust: 0.6

vendor:samsungmodel:mobile devices qscope: - version: -

Trust: 0.6

vendor:samsungmodel:mobile devices rscope: - version: -

Trust: 0.6

vendor:samsungmodel:mobile devices oscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-65258 // JVNDB: JVNDB-2020-011935 // NVD: CVE-2020-26604

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-26604
value: HIGH

Trust: 1.0

NVD: CVE-2020-26604
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-65258
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202010-166
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-26604
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-65258
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-26604
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2020-26604
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-65258 // JVNDB: JVNDB-2020-011935 // CNNVD: CNNVD-202010-166 // NVD: CVE-2020-26604

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Improper authority management (CWE-269) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-011935 // NVD: CVE-2020-26604

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202010-166

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202010-166

PATCH

title:Top pageurl:https://www.android.com/

Trust: 0.8

title:Patch for Samsung products have unspecified vulnerabilities (CNVD-2020-65258)url:https://www.cnvd.org.cn/patchInfo/show/240673

Trust: 0.6

title:Measures to fix security vulnerabilities in Samsung mobile devicesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=130210

Trust: 0.6

sources: CNVD: CNVD-2020-65258 // JVNDB: JVNDB-2020-011935 // CNNVD: CNNVD-202010-166

EXTERNAL IDS

db:NVDid:CVE-2020-26604

Trust: 3.0

db:JVNDBid:JVNDB-2020-011935

Trust: 0.8

db:CNVDid:CNVD-2020-65258

Trust: 0.6

db:NSFOCUSid:50367

Trust: 0.6

db:CNNVDid:CNNVD-202010-166

Trust: 0.6

sources: CNVD: CNVD-2020-65258 // JVNDB: JVNDB-2020-011935 // CNNVD: CNNVD-202010-166 // NVD: CVE-2020-26604

REFERENCES

url:https://security.samsungmobile.com/securityupdate.smsb

Trust: 3.0

url:https://nvd.nist.gov/vuln/detail/cve-2020-26604

Trust: 1.4

url:http://www.nsfocus.net/vulndb/50367

Trust: 0.6

sources: CNVD: CNVD-2020-65258 // JVNDB: JVNDB-2020-011935 // CNNVD: CNNVD-202010-166 // NVD: CVE-2020-26604

SOURCES

db:CNVDid:CNVD-2020-65258
db:JVNDBid:JVNDB-2020-011935
db:CNNVDid:CNNVD-202010-166
db:NVDid:CVE-2020-26604

LAST UPDATE DATE

2024-11-23T22:29:27.744000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-65258date:2020-11-23T00:00:00
db:JVNDBid:JVNDB-2020-011935date:2021-04-20T03:26:00
db:CNNVDid:CNNVD-202010-166date:2021-08-16T00:00:00
db:NVDid:CVE-2020-26604date:2024-11-21T05:20:08.697

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-65258date:2020-10-21T00:00:00
db:JVNDBid:JVNDB-2020-011935date:2021-04-20T00:00:00
db:CNNVDid:CNNVD-202010-166date:2020-10-06T00:00:00
db:NVDid:CVE-2020-26604date:2020-10-06T19:15:15.180