CVE-2024-54916

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.
Configurations

No configuration.

History

18 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

18 Feb 2025, 18:15

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : unknown
Summary
  • (es) Un problema en la clase SharedConfig de Telegram Android APK v.11.7.0 permite que un atacante físicamente próximo evite la autenticación y escale privilegios manipulando el valor de retorno del método checkPasscode.

12 Feb 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-287

11 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 23:15

Updated : 2025-03-18 15:15


NVD link : CVE-2024-54916

Mitre link : CVE-2024-54916

CVE.ORG link : CVE-2024-54916


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization