CVE-2023-42579

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

12 Dec 2023, 21:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory
CPE cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
CWE CWE-319
First Time Samsung
Samsung samsung Keyboard
Google
Google android

05 Dec 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-05 03:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-42579

Mitre link : CVE-2023-42579

CVE.ORG link : CVE-2023-42579


JSON object : View

Products Affected

google

  • android

samsung

  • samsung_keyboard
CWE
CWE-319

Cleartext Transmission of Sensitive Information