CVE-2023-42579

I

mproper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory

Information

Published : 2023-12-05 03:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42579

Mitre link : CVE-2023-42579

CVE.ORG link : CVE-2023-42579


JSON object : View

CWE
CWE-319

Cleartext Transmission of Sensitive Information