First published: Fri Mar 11 2022(Updated: )
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop by all third-party applications co-located on the device, even those with no permissions granted, exposing the IMEI values to processes without enforcing any access control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluproducts G90 Firmware | ||
Bluproducts G90 | ||
Bluproducts G9 Firmware | ||
Bluproducts G9 | ||
Wikomobile Tommy 3 Firmware | ||
Wikomobile Tommy 3 | ||
Wikomobile Tommy 3 Plus Firmware | ||
Wikomobile Tommy 3 Plus | ||
Luna Simo Firmware | ||
Luna Simo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-41850.
The severity of CVE-2021-41850 is high with a CVSS score of 7.8.
The Luna Simo PPR1.180610.011/202001031830 firmware version is affected by CVE-2021-41850.
The system property values can be obtained via getprop by all third-party applications co-located on the device.
No, the Bluproducts G90 and G9 are not affected by CVE-2021-41850.