Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-42579


Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.


Published

2023-12-05T03:15:18.967

Last Modified

2024-11-21T08:22:49.837

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application samsung samsung_keyboard < 5.3.70.1 Yes
Application samsung samsung_keyboard < 5.4.60.49 Yes
Application samsung samsung_keyboard < 5.4.85.5 Yes
Application samsung samsung_keyboard < 5.5.00.58 Yes
Operating System google android 11.0 No
Application samsung samsung_keyboard < 5.3.70.1 Yes
Application samsung samsung_keyboard < 5.6.00.52 Yes
Application samsung samsung_keyboard < 5.6.10.42 Yes
Application samsung samsung_keyboard < 5.7.00.45 Yes
Operating System google android 12.0 No
Application samsung samsung_keyboard < 5.3.70.1 Yes
Operating System google android 13.0 No

References