CVE-2023-22473

LOW

Nextcloud Talk < 15.0.2 - Improper Access Control via Passcode Bypass

Title source: llm
STIX 2.1

Description

Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.

References (3)

Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/nextcloud/talk-android/pull/2598
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1784645

Scores

CVSS v3 2.1
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
nextcloud/talk < 15.0.2
Published Jan 09, 2023
Tracked Since Feb 18, 2026