CVE-2018-14979

The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package name of com.asus.loguploader (versionCode=1570000275, versionName=7.0.0.55_170515). This app contains an exported service app component named com.asus.loguploader.LogUploaderService that, when accessed with a particular action string, will write a bugreport (kernel log, logcat log, and the state of system services including the text of active notifications), Wi-Fi Passwords, and other system data to external storage (sdcard). Any app with the READ_EXTERNAL_STORAGE permission on this device can read this data from the sdcard after it has been dumped there by the com.asus.loguploader. Third-party apps are not allowed to directly create a bugreport or access the user's stored wireless network credentials.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:zenfone_3_max_firmware:7.0.0.55:*:*:*:*:*:*:*
cpe:2.3:h:asus:zenfone_3_max:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-12-28 21:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-14979

Mitre link : CVE-2018-14979

CVE.ORG link : CVE-2018-14979


JSON object : View

Products Affected

asus

  • zenfone_3_max_firmware
  • zenfone_3_max
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor


NetmanageIT Website NetmanageIT OSINT Web NetmanageIT OpenCTI NetmanageIT PDF Tools NetmanageIT CVE Database NetmanageIT CTO Corner Blog NetmanageIT CTO Corner Blog NetmanageIT Password Pusher NetmanageIT Internet Health and Latency Dashboard NetmanageIT Internet Health and Latency Dashboard NetmanageIT Ubuntu Mirror 10Gbps Copyright OpenCVE 2024