Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infinix Mobile
Infinix Mobile com.transmission.agingfunction |
|
CPEs | cpe:2.3:a:infinix_mobile:com.transmission.agingfunction:13:*:*:*:*:*:*:* | |
Vendors & Products |
Infinix Mobile
Infinix Mobile com.transmission.agingfunction |
|
Metrics |
ssvc
|
Wed, 04 Dec 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions. After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices. | |
Title | Unauthorized factory reset of Infinix devices | |
Weaknesses | CWE-925 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-12-04T12:02:22.601Z
Updated: 2024-12-04T21:01:06.241Z
Reserved: 2024-10-31T10:16:21.663Z
Link: CVE-2024-10576
Vulnrichment
Updated: 2024-12-04T20:04:28.995Z
NVD
Status : Received
Published: 2024-12-04T12:15:18.463
Modified: 2024-12-04T12:15:18.463
Link: CVE-2024-10576
Redhat
No data.