← volver
CVE-2023-38290

CVE-2023-38290

CVSS 7.8 HIGHEPSS 0.2%CWE-1263
En resumen

Una app preinstalada en celulares BLU View 2 y Sharp Rouvo V tiene controles de seguridad débiles que permiten a cualquier app instalada ejecutar comandos poderosos del sistema sin permiso, permitiendo robo de datos, instalación de malware, grabación de pantalla o borrado del dispositivo.

Detalle técnico

El CVE-2023-38290 afecta la aplicación preinstalada com.evenwell.fqc (versiones 9.0208.01, 9.0209.13, 9.0212.03) mediante control de acceso inadecuado (CWE-1263), permitiendo que apps locales de terceros ejecuten comandos shell arbitrarios con privilegios de sistema sin requerir permisos declarados ni interacción del usuario. La vulnerabilidad permite que apps maliciosas realicen operaciones sensibles incluyendo otorgamiento de permisos arbitrarios, instalación de apps, grabación de pantalla, reinicio de fábrica, inyección de entrada y acceso a notificaciones.

Resumen generado y traducido por IA a partir de la descripción oficial.
Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode='9020801', versionName='9.0208.01' ; versionCode='9020913', versionName='9.0209.13' ; versionCode='9021203', versionName='9.0212.03') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.evenwell.fqc app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user's apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1663816427:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1656476696:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1647856638:user/release-keys) and Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_460:user/release-keys and SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys). This malicious app starts an exported activity named com.evenwell.fqc/.activity.ClickTest, crashes the com.evenwell.fqc app by sending an empty Intent (i.e., having not extras) to the com.evenwell.fqc/.FQCBroadcastReceiver receiver component, and then it sends command arbitrary shell commands to the com.evenwell.fqc/.FQCService service component which executes them with "system" privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/a

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →