Exported Service Vulnerability in ASUS ZenFone 3 Max Device
CVE-2018-14979
4.7MEDIUM
Summary
The ASUS ZenFone 3 Max contains a pre-installed app that exposes sensitive system data. This vulnerability arises from the app's exported service component, which allows unauthorized access to a bug report, Wi-Fi passwords, and other critical system information. Any application with READ_EXTERNAL_STORAGE permissions can access this sensitive information after it is dumped to external storage, thereby posing serious security risks to users. Mitigating the impact of this vulnerability requires careful management of app permissions and user awareness regarding data privacy.
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved