Authorization Flaw in Ulefone Armor 5 Android Device
CVE-2019-15354

5.5MEDIUM

Key Information:

Vendor

Ulefone

Vendor
CVE Published:
14 November 2019

What is CVE-2019-15354?

The Ulefone Armor 5 Android device features a serious authorization flaw due to a pre-installed application identified by the package name com.mediatek.wfo.impl. This vulnerability allows any app located on the same device to modify critical system properties via an exported interface without adequate authorization checks. This can potentially enable malicious applications to alter system settings, posing risks to device integrity and user security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.