{ "schema_version": "1.4.0", "id": "GHSA-h3pf-mvgp-g8g3", "modified": "2022-05-14T03:37:03Z", "published": "2022-05-14T03:37:03Z", "aliases": [ "CVE-2017-10963" ], "details": "In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence. This installed application can further leak information stored inside the Knox container to the outside world.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-10963" }, { "type": "WEB", "url": "https://gist.github.com/e96e02/12ce905e3b724954273dd7d543a968f1" }, { "type": "WEB", "url": "https://www.lgsinnovations.com/lgs-innovations-discovers-samsung-mobile-product-security-vulnerability" } ], "database_specific": { "cwe_ids": [ "CWE-74" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2018-02-20T19:29:00Z" } }