20040427 Phenoelit Advisory <wir-haben-auch-mal-was-gefunden #0815 ++++>mailing list
http://marc.info/?l=full-disclosure&m=108308895624565&w=2 CVE-2004-2626
Siemens S55 - Cellular Telephone Sms Confirmation Message Bypass
Record summary
CVE-2004-2626 has a selected CVSS score of 3.7; EIP currently links 1 catalogued exploit.
Description
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSiemens S55 - Cellular Telephone Sms Confirmation Message BypassExploitDB exploitby FtRNot analyzed1 file
References
820040429 Re: Phenoelit Advisorymailing list
http://marc.info/?l=full-disclosure&m=108325033624812&w=2 11492Third-party advisory
http://secunia.com/advisories/11492 1009959vdb entry
http://securitytracker.com/alerts/2004/Apr/1009959.html 5703vdb entry
http://www.osvdb.org/5703 10227vdb entry
http://www.securityfocus.com/bid/10227 siemens-unauth-sms-message(15995)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15995 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2626