2.6

CVE-2011-4872

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

Data is provided by the National Vulnerability Database (NVD)
HtcDesire Hd Versionfrg83d
HtcDesire Hd Versiongri40
HtcDesire S Versiongri40
HtcDroid Incredible Versionfrf91
HtcEvo 3d Versiongri40
HtcEvo 4g Versiongri40
HtcGlacier Versionfrg83
HtcSensation 4g Versiongri40
HtcSensation Z710e Versiongri40
HtcThunderbolt 4g Versionfrg83d
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.48% 0.803
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.