First published: Tue May 29 2012(Updated: )
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =2.3.4 | |
ZTE Score M |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2949 is considered a high severity vulnerability due to the use of a hardcoded password that allows remote attackers to gain privileges.
To fix CVE-2012-2949, users should update their device firmware to a version that removes the hardcoded password or implement other access control measures.
CVE-2012-2949 affects devices running Android 2.3.4, specifically the Zte Score M smartphone.
CVE-2012-2949 allows remote attackers to execute crafted applications that can gain unauthorized access to device commands.
CVE-2012-2949 is not typically an issue for current devices as it pertains to an outdated Android version and specific older hardware.