5.5

CVE-2021-41849

Exploit
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bluproducts ≫ G90 Firmware Version -
   Bluproducts ≫ G90 Version -
Bluproducts ≫ G9 Firmware Version -
   Bluproducts ≫ G9 Version -
Wikomobile ≫ Tommy 3 Firmware Version -
   Wikomobile ≫ Tommy 3 Version -
Wikomobile ≫ Tommy 3 Plus Firmware Version -
   Wikomobile ≫ Tommy 3 Plus Version -
Luna ≫ Simo Firmware Version -
   Luna ≫ Simo Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.166
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://athack.com/session-details/401
Third Party Advisory
https://simowireless.com/
Vendor Advisory
https://www.kryptowire.com/android-firmware-2022/
Broken Link
https://www.kryptowire.com/blog/vsim-vulnerability-within-simo-android-phones-exposed/
Third Party Advisory
Exploit