CVE-2018-14825 Details
Description
On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running Android OS 6.0, CT50 running Android OS 4.4, D75e running Android OS 4.4, CN51 running Android OS 6.0, EDA50k running Android 4.4, EDA50 running Android OS 7.1, EDA50k running Android OS 7.1, EDA70 running Android OS 7.1, EDA60k running Android OS 7.1, and EDA51 running Android OS 8.1), a skilled attacker with advanced knowledge of the target system could exploit this vulnerability by creating an application that would successfully bind to the service and gain elevated system privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.vde.com/de-de/advisories/vde-2018-016 | CVE | Third Party Advisory |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-256-01 | CVE | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/105767 | CVE | Third Party AdvisoryVDB Entry |
| https://cert.vde.com/de-de/advisories/vde-2018-016 | [email protected] | Third Party Advisory |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-256-01 | [email protected] | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/105767 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| honeywell cn80 | All versions |
CPE
Remediation
| |
| honeywell ct40 | All versions |
CPE
Remediation
| |
| honeywell ct60 | All versions |
CPE
Remediation
| |
| honeywell eda50 | All versions |
CPE
Remediation
| |
| honeywell eda50k | All versions |
CPE
Remediation
| |
| honeywell eda60k | All versions |
CPE
Remediation
| |
| honeywell eda70 | All versions |
CPE
Remediation
| |
| google android | 7.1.0 6.0 4.4 8.1 |
CPE
Remediation
| |
| honeywell ck75 | All versions |
CPE
Remediation
| |
| honeywell cn51 | All versions |
CPE
Remediation
| |
| honeywell cn75 | All versions |
CPE
Remediation
| |
| honeywell cn75e | All versions |
CPE
Remediation
| |
| honeywell d75e | All versions |
CPE
Remediation
| |
| honeywell ct50 | All versions |
CPE
Remediation
| |
| honeywell eda51 | All versions |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Dec 20, 2018 | Initial Analysis | [email protected] |
| Nov 1, 2018 | CVE Modified | [email protected] |
| Oct 22, 2018 | CVE Modified | [email protected] |
| Sep 24, 2018 | CVE Modified | [email protected] |