Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-4031


Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices allow attackers to send AT commands by plugging the device into a Linux host, aka SVE-2016-5301.


Published

2017-04-13T16:59:01.207

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System samsung galaxy_s6_firmware g920fxxu2coh2 Yes
Hardware samsung galaxy_s6 - No
Operating System samsung galaxy_note_3_firmware n9005xxugbob6 Yes
Hardware samsung galaxy_note_3 - No
Operating System samsung galaxy_s4_mini_firmware i9192xxubnb1 Yes
Hardware samsung galaxy_s4_mini - No
Operating System samsung galaxy_s4_mini_lte_firmware i9195xxucol1 Yes
Hardware samsung galaxy_s4_mini_lte - No
Operating System samsung galaxy_s4_firmware i9505xxuhoj2 Yes
Hardware samsung galaxy_s4 - No

References