First published: Tue Apr 07 2020(Updated: )
An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy S5 Firmware | ||
Samsung Galaxy S5 | ||
Samsung Galaxy Note 3 firmware | ||
Samsung Galaxy Note 3 firmware | ||
Samsung Galaxy S4 Firmware | ||
Samsung Galaxy S4 Firmware | ||
Samsung Galaxy Note 2 firmware | ||
Samsung Galaxy Note 2 firmware | ||
Samsung Galaxy S3 Firmware | ||
Samsung S3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-11050 has a severity rating that indicates potential critical impacts due to the ability for attackers to rewrite the IMEI of affected devices.
To mitigate CVE-2016-11050, ensure your Samsung device firmware is updated to the latest version provided by Samsung.
CVE-2016-11050 affects Samsung mobile devices such as S3, Note2, S4, Note3, and S5 on specific firmware versions.
CVE-2016-11050 requires physical access to the device, as an attacker must flash crafted firmware to exploit the vulnerability.
CVE-2016-11050 enables attackers to rewrite the IMEI number of affected Samsung devices, potentially compromising device identity.