CVE-2023-42579

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory

12 Dec 2023, 21:22

Type Values Removed Values Added
First Time Google
Google android
Samsung samsung Keyboard
Samsung
CWE CWE-319
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory

05 Dec 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-05 03:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42579

Mitre link : CVE-2023-42579

CVE.ORG link : CVE-2023-42579


JSON object : View

Products Affected

samsung

  • samsung_keyboard

google

  • android
CWE
CWE-319

Cleartext Transmission of Sensitive Information