CVE-2012-2217
The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost…
Does this matter?
Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.
Description
The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- htc/evo 4g software · htc/evo 4g · htc/evo design 4g software · htc/evo design 4g · htc/shift 4g software · htc/shift 4g · htc/evo 3d software · htc/evo 3d · htc/evo view 4g software · htc/evo view 4g · htc/vivid software · htc/vivid · htc/hero software · htc/hero
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0176.html
- http://www.securityfocus.com/bid/53187
- http://www.vsecurity.com/resources/advisory/20120420-1/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75080
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0176.html
- http://www.securityfocus.com/bid/53187
- http://www.vsecurity.com/resources/advisory/20120420-1/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75080
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.