CVE-2019-9939
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2019
Last modified:
24/08/2020
Description
The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to bypass authentication by trying to fetch a non-existing page. When the non-existing page is requested, the application responds with a 200 status code and empty page, and adds the requesting client device into the list of recognized devices.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ushareit:shareit:*:*:*:*:*:android:*:* | 4.0.34 (including) |
To consult the complete list of CPE names with products and versions, see this page



