CVE-2023-38299

April 22, 2024, 7:24 p.m.

None
No Score

Description

Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: AT&T Calypso (ATT/U318AA/U318AA:10/QP1A.190711.020/1632369780:user/release-keys); Nokia C100 (Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_190:user/release-keys and Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_270:user/release-keys); Nokia C200 (Nokia/Drake_02US/DRK:12/SP1A.210812.016/02US_1_080:user/release-keys); and BLU View 3 (BLU/B140DL/B140DL:11/RP1A.200720.011/1628014629:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1632535579:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1637325978:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1650073052:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1657087912:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1666316280:user/release-keys, and BLU/B140DL/B140DL:11/RP1A.200720.011/1672371162:user/release-keys). This malicious app reads from the "persist.sys.imei1" system property to indirectly obtain the device IMEI.

Product(s) Impacted

Product Versions
AT&T Calypso
  • ATT/U318AA/U318AA:10/QP1A.190711.020/1632369780:user/release-keys
Nokia C100
  • Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_190:user/release-keys
  • Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_270:user/release-keys
Nokia C200
  • Nokia/Drake_02US/DRK:12/SP1A.210812.016/02US_1_080:user/release-keys
BLU View 3
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1628014629:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1632535579:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1637325978:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1650073052:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1657087912:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1666316280:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1672371162:user/release-keys
ATT Calypso
  • Device build fingerprint: ATT/U318AA/U318AA:10/QP1A.190711.020/1632369780:user/release-keys
Nokia C100
  • Device build fingerprints: Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_190:user/release-keys
  • Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_270:user/release-keys
Nokia C200
  • Device build fingerprint: Nokia/Drake_02US/DRK:12/SP1A.210812.016/02US_1_080:user/release-keys
BLU View 3
  • Device build fingerprints: BLU/B140DL/B140DL:11/RP1A.200720.011/1628014629:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1632535579:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1637325978:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1650073052:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1657087912:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1666316280:user/release-keys
  • BLU/B140DL/B140DL:11/RP1A.200720.011/1672371162:user/release-keys

Weaknesses

Tags

Date

  • Published: April 22, 2024, 3:15 p.m.
  • Last Modified: April 22, 2024, 7:24 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.