← volver
CVE-2024-34130

Acrobat Android : OverSecured Finding : Access to arbitrary* content providers via insecure Intent configuration

CVSS 5.5 MEDIUMEPSS 0.3%CWE-863
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
13 jun 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N