CVE-2018-6599
Last modified
CVE-2018-6599 is a vulnerability of currently unknown severity. An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card. The system-wide Android logs are not directly available to third-party apps since they tend to contain sensitive data. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card. The system-wide Android logs are not directly available to third-party apps since they tend to contain sensitive data. Third-party apps can read from the log but only the log messages that the app itself has written. Certain apps can leak data to the Android log due to not sanitizing log messages, which is in an insecure programming practice. Pre-installed system apps and apps that are signed with the framework key can read from the system-wide Android log. We found a pre-installed app on the Orbic Wonder that when started via an Intent will write the Android log to the SD card, also known as external storage, via com.ckt.mmitest.MmiMainActivity. Any app that requests the READ_EXTERNAL_STORAGE permission can read from the SD card. Therefore, a local app on the device can quickly start a specific component in the pre-installed system app to have the Android log written to the SD card. Therefore, any app co-located on the device with the READ_EXTERNAL_STORAGE permission can obtain the data contained within the Android log and continually monitor it and mine the log for relevant data. In addition, the default messaging app (com.android.mms) writes the body of sent and received text messages to the Android log, as well as the recipient phone number for sent text messages and the sending phone number for received text messages. In addition, any call data contains phone numbers for sent and received calls.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Orbic | Wonder Rc555l Firmware | 7.1 |
| Orbic | Wonder Rc555l Firmware | 7.1.2 |
References
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Third Party Advisory
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6599?
How severe is CVE-2018-6599?
How do I fix CVE-2018-6599?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-6592Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow …
- CVE-2018-6593An issue was discovered in MalwareFox AntiMalware 2.74.0.150…
- CVE-2018-6594lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 ge…
- CVE-2018-6596webhooks/base.py in Anymail (aka django-anymail) before 1.2.…
- CVE-2018-6597The Alcatel A30 device with a build fingerprint of TCL/5046G…
- CVE-2018-6598An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:…
- CVE-2018-6603Promise Technology WebPam Pro-E devices allow remote attacke…
- CVE-2018-6604SQL Injection exists in the Zh YandexMap 6.2.1.0 component f…
- CVE-2018-6605SQL Injection exists in the Zh BaiduMap 3.0.0.1 component fo…
- CVE-2018-6606An issue was discovered in MalwareFox AntiMalware 2.74.0.150…
- CVE-2018-6608In the WebRTC component in Opera 51.0.2830.55, after visitin…
- CVE-2018-6609SQL Injection exists in the JSP Tickets 1.1 component for Jo…
Are you affected by CVE-2018-6599?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
