SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-4872

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain…

LOW 2.6EPSS 1.40%

Does this matter?

Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
1.40% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
htc/desire hd · htc/desire s · htc/droid incredible · htc/evo 3d · htc/evo 4g · htc/glacier · htc/sensation 4g · htc/sensation z710e · htc/thunderbolt 4g
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.