Local Access Control Weakness in Third-Party Android App by com.factory.mmigroup
CVE-2023-38297

8.4HIGH

Key Information:

Vendor
CVE Published:
22 April 2024

What is CVE-2023-38297?

A local access control weakness exists in the com.factory.mmigroup component, found across various Android device models. The vulnerability allows third-party applications to exploit functions exposed by the vulnerable pre-installed app. Due to insufficient access control, these applications can perform potentially harmful actions, such as executing arbitrary AT commands, conducting unauthorized factory resets, leaking sensitive information like IMEI and serial numbers, and controlling device settings without user permissions. The security implications depend on the specific device, but the risks are heightened for devices that utilize affected builds of the com.factory.mmigroup application, which runs with system-level privileges.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.