5

CVE-2012-3887

Exploit

AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows remote attackers to obtain sensitive information by sniffing the local wireless network, as demonstrated by the SMS message content sent to the sdctl/sms/send/single/ URI.

Data is provided by the National Vulnerability Database (NVD)
AirdroidAirdroid Updatebeta Version <= 1.0.6
AirdroidAirdroid Version1.0.1
AirdroidAirdroid Version1.0.2
AirdroidAirdroid Version1.0.3
AirdroidAirdroid Version1.0.4
AirdroidAirdroid Version1.0.4 Updatebeta
AirdroidAirdroid Version1.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.455
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N