MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2019-6744

CVSS 4.3v3.1pub. 2020-02-10upd. 2024-11-21

This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. Was ZDI-CAN-7381.

CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Samsung Galaxy S9

    HW
    Samsung
    all versions
  • Samsung Knox

    APP
    Samsung
    1.2.02.39
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
ContainerAuth Bypass
CWE
References

Related vulnerabilities

CVE-2019-6742CRITICAL9.8PL ✓same product

RCE w mechanizmie aktualizacji GameServiceReceiver na Samsung Galaxy S9

CVE-2019-6741CRITICAL9.3PL ✓same product

RCE w captive portal Samsung Galaxy S9 — przekierowanie HTML

CVE-2019-6740HIGH8.8same product

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Ga...

CVE-2016-1920MEDIUM5.5same product

Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-midd...

CVE-2016-3996MEDIUM5.5same product

ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users ...