Vulnerabilities > CVE-2019-7386

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
kaiostech
nokia

Summary

A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device.

Vulnerable Configurations

Part Description Count
OS
Kaiostech
1
OS
Nokia
1
Hardware
Nokia
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/151651/KSA-DEV-007.txt
idPACKETSTORM:151651
last seen2019-02-14
published2019-02-13
reporterKaustubh G. Padwad
sourcehttps://packetstormsecurity.com/files/151651/Nokia-8810-Denial-Of-Service.html
titleNokia 8810 Denial Of Service