CVE-2023-42579

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

12 Dec 2023, 21:22

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 - Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3
CWE CWE-319
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:a:samsung:samsung_keyboard:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
First Time Google
Samsung
Google android
Samsung samsung Keyboard

05 Dec 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-05 03:15

Updated : 2023-12-12 21:22


NVD link : CVE-2023-42579

Mitre link : CVE-2023-42579

CVE.ORG link : CVE-2023-42579


JSON object : View

Products Affected

samsung

  • samsung_keyboard

google

  • android
CWE
CWE-319

Cleartext Transmission of Sensitive Information