CVE-2012-2949
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
29/05/2012
Last modified:
11/04/2025
Description
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:android:2.3.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:zte:score_m:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://blog.mylookout.com/blog/2012/05/21/zte-security-vulnerability
- http://www.pcmag.com/article2/0%2C2817%2C2404639%2C00.asp
- http://www.reuters.com/article/2012/05/18/us-zte-phone-idUSBRE84H08J20120518
- http://blog.mylookout.com/blog/2012/05/21/zte-security-vulnerability
- http://www.pcmag.com/article2/0%2C2817%2C2404639%2C00.asp
- http://www.reuters.com/article/2012/05/18/us-zte-phone-idUSBRE84H08J20120518



