Vulnerable Mobile Software Management Tool Reaches Into IoT
ID: 0d1c74e6-63e7-55b8-aa4b-f40e45454c60
STIX ID: report--0d1c74e6-63e7-55b8-aa4b-f40e45454c60
Feed Name: Security Ledger
The article reports Accuvant researchers identifying authentication weaknesses and memory-corruption vulnerabilities in Red Bend's vDirect Mobile system-management client, software embedded in many mobile baseband controllers and deployed on billions of devices. The flaws could allow remote attackers—who must typically operate a nearby rogue cellular base station and know device configuration—to authenticate to or gain control of the MSM client, potentially affecting phones and other embedded systems (including connected vehicles); researchers did not publish exploits and only specific device models were confirmed vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
