#VU70794 Improper access control in Nextcloud Android Talk - CVE-2023-22473


Vulnerability identifier: #VU70794

Vulnerability risk: Low

CVSSv4.0: 0.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-22473

CWE-ID: CWE-284

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Nextcloud Android Talk
Client/Desktop applications / Messaging software

Vendor: Nextcloud

Description

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass of passcode and access the user's Nextcloud files and view conversations.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Nextcloud Android Talk: before 15.0.2


External links
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wvr4-gc4c-6vmx


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability