VDB
CVE-2014-8610
CVE-2014-8610
PUBLISHED
CVSS 3.299999952316284 LOW
AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows attackers to send stored SMS messages, and consequently transmit arbitrary new draft SMS messages or trigger additional per-message charges from a network operator for old messages, via a crafted application that broadcasts an intent with the com.android.mms.transaction.MESSAGE_SENT action, aka Bug 17671795.
EPSS 0.34% · 27.8th percentile
Risk Scores
CVSS 2.0
3.299999952316284
EPSS Score
0.34%
27.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 1.1, 1.5, 1.6 | |
| n/a | n/a | n/a |
Timeline
- Nov 26, 2014 PoC Published
- Dec 15, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
References
- http://xteam.baidu.com/?p=164 url
- https://android.googlesource.com/platform/packages/apps/Mms/+/008d6202fca4002a7dfe333f22377faa73585c67 url
- https://github.com/joswr1ght/drozer-modules/blob/master/whfs/smsdraftsend.py url
- 20141126 CVE-2014-8610 Android < 5.0 SMS resend vulnerability mailing-list
- 20141203 Re: CVE-2014-8610 Android < 5.0 SMS resend vulnerability mailing-list
- http://packetstormsecurity.com/files/129282/Android-SMS-Resend.html url
- https://nvd.nist.gov/vuln/detail/CVE-2014-8610 advisory