CVE-2018-16270

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
22/01/2020
Last modified:
30/01/2020

Description

Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:samsung:galaxy_gear_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:galaxy_gear:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_2_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:gear_2:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_live_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:gear_live:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_s_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:gear_s:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_s2_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:gear_s2:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_s3_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:gear_s3:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_sport_firmware:*:*:*:*:*:*:*:* re2 (excluding)
cpe:2.3:h:samsung:gear_sport:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:gear_fit_firmware:*:*:*:*:*:*:*:* re2 (excluding)