An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certificate. The Samsung ID is SVE-2017-9659 (September 2017).
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 6.0 (including) | 6.0 (including) | |
Android | 7.0 (including) | 7.0 (including) | |
Android | 7.1 (including) | 7.1 (including) |