VulnerabilityModified
CVE-2020-25824
An attacker then approaches the unattended desktop and pushes the Export key.
LOW 2.4EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard. The threat model is a victim who has voluntarily opened Export Wizard but is then distracted. An attacker then approaches the unattended desktop and pushes the Export key. This attacker may consequently gain access to all chat conversation and media files.
- CVSS 3.1
- 2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- telegram/telegram desktop
- Source
- cve@mitre.org
References
- https://github.com/soheilsamanabadi/vulnerability/blob/main/Telegram-Desktop-CVE-2020-25824Third Party Advisory
- https://github.com/telegramdesktop/tdesktop/releases/tag/v2.4.3Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/202101-34Third Party Advisory
- https://www.Telegram.orgProduct
- https://github.com/soheilsamanabadi/vulnerability/blob/main/Telegram-Desktop-CVE-2020-25824Third Party Advisory
- https://github.com/telegramdesktop/tdesktop/releases/tag/v2.4.3Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/202101-34Third Party Advisory
- https://www.Telegram.orgProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.