Vulnerabilities > CVE-2019-15367 - Unspecified vulnerability in Haier P10 Firmware

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
local
low complexity
haier

Summary

The Haier P10 Android device with a build fingerprint of Haier/P10/P10:8.1.0/O11019/1532662449:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

Vulnerable Configurations

Part Description Count
OS
Haier
1
Hardware
Haier
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/154232/tableau-xxe.txt
idPACKETSTORM:154232
last seen2019-08-27
published2019-08-27
reporterJarad Kopf
sourcehttps://packetstormsecurity.com/files/154232/Tableau-XML-Injection.html
titleTableau XML Injection