CVE-2011-4872
Last modified
CVE-2011-4872 is a vulnerability of currently unknown severity. Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Htc | Desire Hd | frg83d |
| Htc | Desire Hd | gri40 |
| Htc | Desire S | gri40 |
| Htc | Droid Incredible | frf91 |
| Htc | Evo 3d | gri40 |
| Htc | Evo 4g | gri40 |
| Htc | Glacier | frg83 |
| Htc | Sensation 4g | gri40 |
| Htc | Sensation Z710e | gri40 |
| Htc | Thunderbolt 4g | frg83d |
References
- http://secunia.com/advisories/47837Vendor Advisory
- http://www.kb.cert.org/vuls/id/763355US Government Resource
- http://secunia.com/advisories/47837Vendor Advisory
- http://www.kb.cert.org/vuls/id/763355US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4872?
How severe is CVE-2011-4872?
How do I fix CVE-2011-4872?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4866The Kaixin001 (com.kaixin001.activity) application 1.3.1 and…
- CVE-2011-4867The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 f…
- CVE-2011-4868The logging functionality in dhcpd in ISC DHCP before 4.2.3-…
- CVE-2011-4869validator/val_nsec3.c in Unbound before 1.4.13p2 does not pr…
- CVE-2011-4870Multiple buffer overflows in the (1) GUIControls, (2) BatchO…
- CVE-2011-4871Open Automation Software OPC Systems.NET before 5.0 allows r…
- CVE-2011-4873Unspecified vulnerability in the server in Certec EDV atvise…
- CVE-2011-4874Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1…
- CVE-2011-4875Stack-based buffer overflow in HmiLoad in the runtime loader…
- CVE-2011-4876Directory traversal vulnerability in HmiLoad in the runtime …
- CVE-2011-4877HmiLoad in the runtime loader in Siemens WinCC flexible 2004…
- CVE-2011-4878Directory traversal vulnerability in miniweb.exe in the HMI …
Are you affected by CVE-2011-4872?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
