|
|
On 2017-09-29 23:03, Kurt Seifried wrote: > CVE-2017-9480 is one possible impact (attacker can download config > file) of CVE-2017-9479 (syseventd running as root listening on some > local networks). > If I could plug a cable into your phone and control it with no > further passwords/etc, that'd be a CVE right? Avoiding the physical access discussion for the moment (or accepting your position), why are these two CVE IDs? CVE-2017-9479 https://github.com/BastilleResearch/CableTap/blob/master/doc/advisories/bastille-22.syseventd.txt CVE-2017-9480 https://github.com/BastilleResearch/CableTap/blob/master/doc/advisories/bastille-23.upnp-directory-write.txt - Art