The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
References
Link | Resource |
---|---|
https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf | Exploit Third Party Advisory |
https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-22T13:04:37
Updated: 2020-01-22T13:04:37
Reserved: 2018-08-31T00:00:00
Link: CVE-2018-16272
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-01-22T14:15:11.337
Modified: 2020-01-30T17:54:44.027
Link: CVE-2018-16272
JSON object: View
Redhat Information
No data.
CWE