SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2217

The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost…

MEDIUM 6.4EPSS 2.03%

Does this matter?

Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.

Description

The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.03% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
htc/evo 4g software · htc/evo 4g · htc/evo design 4g software · htc/evo design 4g · htc/shift 4g software · htc/shift 4g · htc/evo 3d software · htc/evo 3d · htc/evo view 4g software · htc/evo view 4g · htc/vivid software · htc/vivid · htc/hero software · htc/hero
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.