Vulnerability Description
The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted application to eavesdrop after phone shutdown or record a conversation. The Samsung ID is SVE-2016-6343.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Samsung Mobile | 6.0 |
Related Weaknesses (CWE)
References
- http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016Vendor Advisory
- http://www.securityfocus.com/bid/94494Third Party AdvisoryVDB Entry
- http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016Vendor Advisory
- http://www.securityfocus.com/bid/94494Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-9567?
CVE-2016-9567 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be expl...
How severe is CVE-2016-9567?
CVE-2016-9567 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9567?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Samsung Mobile.