Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.  After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
History

Wed, 04 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Infinix Mobile
Infinix Mobile com.transmission.agingfunction
CPEs cpe:2.3:a:infinix_mobile:com.transmission.agingfunction:13:*:*:*:*:*:*:*
Vendors & Products Infinix Mobile
Infinix Mobile com.transmission.agingfunction
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 12:15:00 +0000

Type Values Removed Values Added
Description Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.  After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Title Unauthorized factory reset of Infinix devices
Weaknesses CWE-925
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/R:I/V:D/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2024-12-04T12:02:22.601Z

Updated: 2024-12-04T21:01:06.241Z

Reserved: 2024-10-31T10:16:21.663Z

Link: CVE-2024-10576

cve-icon Vulnrichment

Updated: 2024-12-04T20:04:28.995Z

cve-icon NVD

Status : Received

Published: 2024-12-04T12:15:18.463

Modified: 2024-12-04T12:15:18.463

Link: CVE-2024-10576

cve-icon Redhat

No data.