CVE-2024-2365

A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the component SHA-1 Handler. The manipulation leads to password hash with insufficient computational effort. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-256321 was assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kirillmakarov:musicshelf:1.1:*:*:*:*:*:*:*

History

26 Feb 2025, 15:14

Type Values Removed Values Added
References () https://vuldb.com/?id.256321 - () https://vuldb.com/?id.256321 - Permissions Required
References () https://vuldb.com/?ctiid.256321 - () https://vuldb.com/?ctiid.256321 - Permissions Required
References () https://github.com/ctflearner/Android_Findings/blob/main/Musicshelf/Weak_Hashing_Algorithms.md - () https://github.com/ctflearner/Android_Findings/blob/main/Musicshelf/Weak_Hashing_Algorithms.md - Exploit
CPE cpe:2.3:a:kirillmakarov:musicshelf:1.1:*:*:*:*:*:*:*
First Time Kirillmakarov
Kirillmakarov musicshelf
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.2
CWE CWE-916

11 Mar 2024, 01:32

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-11 00:15

Updated : 2025-02-26 15:14


NVD link : CVE-2024-2365

Mitre link : CVE-2024-2365


JSON object : View

Products Affected

kirillmakarov

  • musicshelf
CWE

No CWE.