Vulnerabilities > Asus > Zenfone 3 MAX Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-12-28 CVE-2018-14992 Unspecified vulnerability in Asus Zenfone 3 MAX Firmware 1.5.0.40
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed platform app with a package name of com.asus.dm (versionCode=1510500200, versionName=1.5.0.40_171122) has an exposed interface in an exported service named com.asus.dm.installer.DMInstallerService that allows any app co-located on the device to use its capabilities to download an arbitrary app over the internet and install it.
local
low complexity
asus
5.5
2018-12-28 CVE-2018-14979 Information Exposure vulnerability in Asus Zenfone 3 MAX Firmware 7.0.0.55
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package name of com.asus.loguploader (versionCode=1570000275, versionName=7.0.0.55_170515).
local
high complexity
asus CWE-200
4.7