CVE-2019-12762

MEDIUMCVSS 4.2/10EPSS 0.18%

Last modified

CVE-2019-12762 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.

Metrics

CVSS 3.1
4.2/10

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.18%

8.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
MiMi 5s Plus FirmwareAll versions
SonyXperia Z4 FirmwareAll versions
SamsungGalaxy S6 Edge FirmwareAll versions
SamsungGalaxy S4 FirmwareAll versions
GoogleNexus 7 FirmwareAll versions
GoogleNexus 9 FirmwareAll versions
SharpAquos Zeta Sh-04f FirmwareAll versions
FujitsuArrows Nx F05-F FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-12762?
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.
How severe is CVE-2019-12762?
CVE-2019-12762 has a CVSS score of 4.2/10 (MEDIUM severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2019-12762?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-12762?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST