Unauthorized Wireless Settings Modification in Sony Xperia XZs Device
CVE-2019-15744

3.3LOW

Key Information:

Vendor

Sony

Vendor
CVE Published:
14 November 2019

What is CVE-2019-15744?

The Sony Xperia XZs Android device is affected by a vulnerability that allows unauthorized modification of wireless settings through a pre-installed application. This app, part of the package jp.softbank.mb.tdrl (version 1.3.0), is susceptible to a confused deputy attack, enabling any co-located application on the device to exploit this weakness. This flaw poses significant risks to user privacy and may be leveraged to alter critical device configurations without user consent.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.