Advisory Details

June 24th, 2015

(0Day) (Mobile Pwn2Own) Samsung SBeam Image Remote Information Disclosure Vulnerability

ZDI-15-257
ZDI-CAN-2614

CVE ID CVE-2015-4033
CVSS SCORE 3.3, AV:A/AC:L/Au:N/C:P/I:N/A:N
AFFECTED VENDORS Samsung
AFFECTED PRODUCTS SBeam
VULNERABILITY DETAILS


This vulnerability allows remote attackers to copy images from vulnerable installations of Samsung SBeam. User interaction is required to exploit this vulnerability in that the target must be within range of a hostile NFC transmitter.

The specific flaw exists within the handling of the SBeam peer-to-peer wireless connection. As soon as the connection is initiated with NFC, a vulnerable device will launch an HTTP server on port 15000. This server allows a remote attacker to download any or all images on the vulnerable device without notification or user interaction.

ADDITIONAL DETAILS


This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 120 day deadline.

11/11/2015 - ZDI disclosed this report from Mobile Pwn2Own to the vendor
11/11/2015 - The vendor re-sent ZDI an encryption key
11/11/2015 - ZDI then re-disclosed this report from Mobile Pwn2Own to the vendor
03/13/2015 - ZDI requested a status update
05/13/2015 - ZDI requested a status update
05/18/2015 - ZDI requested a status update

-- Vendor Response:

Fixes for both issues ZDI-CAN-2613 and ZDI-CAN-2614 require FOTA updates from carriers, such that there is no link to a patch for these fixes. While we believe only a small number of devices haven't received the software (FOTA) update from their respective carriers, there are number of devices still at risk from those vulnerabilities.


DISCLOSURE TIMELINE
  • 2014-11-13 - Vulnerability reported to vendor
  • 2015-06-24 - Coordinated public release of advisory
CREDIT Rob Miller and Jon Butler, MWR Labs (@mwrlabs)
BACK TO ADVISORIES