CVE Vulnerabilities

CVE-2016-11044

Improper Verification of Cryptographic Signature

Published: Apr 07, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an applications signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle6.0 (including)6.0 (including)

References