CVE-2016-11041

MEDIUM

Samsung Android KK(4.4) - Lockscreen Bypass via AT Command over USB

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 4.6
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
google/android 4.4
Published Apr 07, 2020
Tracked Since Feb 18, 2026