VDB
CVE-2011-4872
CVE-2011-4872
PUBLISHED
CVSS 2.5999999046325684 LOW
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
EPSS 1.40% · 69.8th percentile
Risk Scores
CVSS 2.0
2.5999999046325684
EPSS Score
1.40%
69.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a, n/a |
| htc | desire_s | gri40, * |
| htc | droid_incredible | frf91, * |
| htc | evo_4g | *, gri40 |
| htc | sensation_z710e | gri40, * |
| htc | thunderbolt_4g | *, frg83d |
| htc | desire_hd | gri40, frg83d, * |
| htc | sensation_4g | *, gri40 |
| htc | glacier | frg83, * |
| htc | evo_3d | *, gri40 |
Timeline
- Feb 5, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 20120201 802.1X password exploit on many HTC Android devices mailing-list
- http://secunia.com/advisories/47837 advisory
- http://www.kb.cert.org/vuls/id/763355 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4872 advisory
- http://blog.mywarwithentropy.com/2012/02/8021x-password-exploit-on-many-htc.html url
- http://www.securityfocus.com/bid/51790 technical