CVE-2012-2949: Critical severity android vulnerability
The ZTE syncagent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2949?
CVE-2012-2949 is considered a high severity vulnerability due to the use of a hardcoded password that allows remote attackers to gain privileges.
How do I fix CVE-2012-2949?
To fix CVE-2012-2949, users should update their device firmware to a version that removes the hardcoded password or implement other access control measures.
Who is affected by CVE-2012-2949?
CVE-2012-2949 affects devices running Android 2.3.4, specifically the Zte Score M smartphone.
What type of attack does CVE-2012-2949 allow?
CVE-2012-2949 allows remote attackers to execute crafted applications that can gain unauthorized access to device commands.
Is CVE-2012-2949 still an issue for current devices?
CVE-2012-2949 is not typically an issue for current devices as it pertains to an outdated Android version and specific older hardware.