Back to search
CVE-2016-1920
Published: Jan 27, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20160119 Re: [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3
mailing-list
x_refsource_BUGTRAQ
20160116 [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now