AT Command Injection Vulnerability in Samsung Mobile Devices
CVE-2016-4031

6.8MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
13 April 2017

Summary

Certain Samsung Galaxy devices are susceptible to an AT command injection vulnerability. This issue allows remote attackers to exploit connected devices by sending specially crafted AT commands when the affected device is connected to a Linux host. The vulnerability can be triggered via direct access, potentially leading to unauthorized command execution and manipulation of device settings.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.