HIGH · 7.5

CVE-2018-16269

The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This af...

Vulnerability Description

The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SamsungGalaxy Gear Firmware< re2
SamsungGalaxy Gear-
SamsungGear 2 Firmware< re2
SamsungGear 2-
SamsungGear Live Firmware< re2
SamsungGear Live-
SamsungGear S Firmware< re2
SamsungGear S-
SamsungGear S2 Firmware< re2
SamsungGear S2-
SamsungGear S3 Firmware< re2
SamsungGear S3-
SamsungGear Sport Firmware< re2
SamsungGear Sport-
SamsungGear Fit Firmware< re2
SamsungGear Fit-
SamsungGear Fit 2 Firmware< re2
SamsungGear Fit 2-
SamsungGear Fit 2 Pro Firmware< re2
SamsungGear Fit 2 Pro-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-16269?

CVE-2018-16269 is a vulnerability with a CVSS score of 7.5 (HIGH). The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This af...

How severe is CVE-2018-16269?

CVE-2018-16269 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-16269?

Check the references section above for vendor advisories and patch information. Affected products include: Samsung Galaxy Gear Firmware, Samsung Galaxy Gear, Samsung Gear 2 Firmware, Samsung Gear 2, Samsung Gear Live Firmware.