VDB
CVE-2018-21078
CVE-2018-21078
PUBLISHED
CVSS 7.5 HIGH
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate video calls because SS (Supplementary Service) and USSD (Unstructured Supplementary Service Data) codes are improperly secured. The Samsung ID is SVE-2018-11469 (April 2018).
EPSS 0.35% · 28.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.35%
28.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 6.0, 7.1.0, 7.1.1 | |
| n/a | n/a | n/a |
Timeline
- Apr 8, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Dec 29, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- May 24, 2022 CVE Updated
- Sep 7, 2022 EPSS Score
- Nov 9, 2022 EPSS Score