Samsung Android Phones in Remote Lock Shock - TopicsExpress



          

Samsung Android Phones in Remote Lock Shock infosecurity-magazine/news/samsung-android-phones-remote-lock/ The US National Institute of Standards and Technology (NIST) has warned of a major new zero-day vulnerability in Samsung Android smartphones which could allow a remote attacker to lock the handset. NIST has given the CVE-2014-8346 flaw a CVSS severity rating of 7.8 and an exploitability subscore of 10.0 as it doesn’t require authentication to exploit. It relates to an issue with the Find My Phone service, as explained by NIST here: “The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.” The note links to two YouTube videos here and here posted by a Mohamed A Baset (@SymbianSyMoh) which purport to show the hack in action.
Posted on: Mon, 03 Nov 2014 12:34:04 +0000

Recently Viewed Topics




© 2015