Authentication bypass using an alternate path or channel in Nextcloud Android Talk - CVE-2021-41181
Published: March 14, 2022
Vulnerability identifier: #VU61279
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41181
CWE-ID: CWE-288
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application does not properly detect the lockscreen state when a call is incoming. An attacker with physical access to the locked phone can gain access to the chat messages and files of the user.
Affected software
Nextcloud Android Talk
How to mitigate CVE-2021-41181
Install updates from vendor's website.
Nextcloud Android Talk - update to 12.3.0