CVE-2018-16272: Critical severity samsung galaxy gear firmware vulnerability
The wpasupplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16272?
CVE-2018-16272 is a vulnerability in the wpa_supplicant system service in Samsung Galaxy Gear series, which allows an unprivileged process to fully control the Wi-Fi interface.
How severe is CVE-2018-16272?
CVE-2018-16272 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
Which Samsung devices are affected by CVE-2018-16272?
CVE-2018-16272 affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
How can an unprivileged process exploit CVE-2018-16272?
An unprivileged process can exploit CVE-2018-16272 by manipulating the Wi-Fi interface due to the lack of D-Bus security policy configurations.
Where can I find more information about CVE-2018-16272?
You can find more information about CVE-2018-16272 at the following references: [link1](https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf) [link2](https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be)