Authentication bypass using an alternate path or channel in Nextcloud Android Talk - CVE-2021-41181

 

Authentication bypass using an alternate path or channel in Nextcloud Android Talk - CVE-2021-41181

Published: March 14, 2022


Vulnerability identifier: #VU61279
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41181
CWE-ID: CWE-288
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected application does not properly detect the lockscreen state when a call is incoming. An attacker with physical access to the locked phone can gain access to the chat messages and files of the user.


Affected software

Nextcloud Android Talk

How to mitigate CVE-2021-41181

Install updates from vendor's website.

Nextcloud Android Talk - update to 12.3.0

External References

Related Security Bulletins