CVE-2011-4872
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain…
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- htc/desire hd · htc/desire s · htc/droid incredible · htc/evo 3d · htc/evo 4g · htc/glacier · htc/sensation 4g · htc/sensation z710e · htc/thunderbolt 4g
- Source
- cret@cert.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0002.html
- http://blog.mywarwithentropy.com/2012/02/8021x-password-exploit-on-many-htc.html
- http://secunia.com/advisories/47837Vendor Advisory
- http://www.kb.cert.org/vuls/id/763355US Government Resource
- http://www.securityfocus.com/bid/51790
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0002.html
- http://blog.mywarwithentropy.com/2012/02/8021x-password-exploit-on-many-htc.html
- http://secunia.com/advisories/47837Vendor Advisory
- http://www.kb.cert.org/vuls/id/763355US Government Resource
- http://www.securityfocus.com/bid/51790
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.