Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-4872


Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.


Published

2012-02-05T11:55:03.047

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.6 (LOW)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

4.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware htc desire_hd frg83d Yes
Hardware htc desire_hd gri40 Yes
Hardware htc desire_s gri40 Yes
Hardware htc droid_incredible frf91 Yes
Hardware htc evo_3d gri40 Yes
Hardware htc evo_4g gri40 Yes
Hardware htc glacier frg83 Yes
Hardware htc sensation_4g gri40 Yes
Hardware htc sensation_z710e gri40 Yes
Hardware htc thunderbolt_4g frg83d Yes

References