CVE Published: 06/11/2024 |
CVE Updated: 06/11/2024 |
CVE Year: 2024 Source: SamsungMobile |
Vendor: Samsung Mobile |
Product: Blockchain Keystore Status : PUBLISHED
CVE-2024-49406 Description
Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering this vulnerability.
Metrics
CVSS Version: 3.1 |
Base Score: 6.7 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* LOW Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* UNCHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE Name: CWE-354 Improper Validation of Integrity Check Value Source: Samsung Mobile
Common Attack Pattern Enumeration and Classification (CAPEC)