MEDIUM · 6.4

CVE-2012-2217

The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before...

Vulnerability Description

The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
HtcEvo 4G Software<= 4.54.651.1
HtcEvo 4G-
HtcEvo Design 4G Software<= 1.19.651.1
HtcEvo Design 4G-
HtcShift 4G Software<= 2.76.651.6
HtcShift 4G-
HtcEvo 3D Software<= 2.08.651.3
HtcEvo 3DAll versions
HtcEvo View 4G Software<= 1.22.651.2
HtcEvo View 4G-
HtcVivid Software<= 3.26.502
HtcVivid-
HtcHero Software1.29.651.1
HtcHero-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2217?

CVE-2012-2217 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before...

How severe is CVE-2012-2217?

CVE-2012-2217 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2217?

Check the references section above for vendor advisories and patch information. Affected products include: Htc Evo 4G Software, Htc Evo 4G, Htc Evo Design 4G Software, Htc Evo Design 4G, Htc Shift 4G Software.