Unauthorized System Property Modification in Panasonic Eluga Ray 600
CVE-2019-15378

5.5MEDIUM

Key Information:

Vendor

Panasonic

Vendor
CVE Published:
14 November 2019

What is CVE-2019-15378?

The Panasonic Eluga Ray 600 Android device has a vulnerability due to a pre-installed app (com.mediatek.wfo.impl) that enables any app on the same device to modify system properties through an exported interface. This flaw occurs without sufficient authorization, potentially compromising the integrity of the device and allowing malicious activities.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.