Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
                
            References
                    | Link | Resource | 
|---|---|
| https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2023-12-05 03:15
Updated : 2023-12-12 21:22
NVD link : CVE-2023-42579
Mitre link : CVE-2023-42579
CVE.ORG link : CVE-2023-42579
JSON object : View
Products Affected
                samsung
- samsung_keyboard
- android
CWE
                
                    
                        
                        CWE-319
                        
            Cleartext Transmission of Sensitive Information
