« Volver al listado

CVE-2017-4895

Estado: ModificadaAlta (8.8)—

Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-4895",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "VMware",
          "product": "Airwatch Agent",
          "versions": [
            {
              "status": "affected",
              "version": "x.x"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-05-10T14:29:00.717",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/95892",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1037738",
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.vmware.com/us/security/advisories/VMSA-2017-0001.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/95892",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1037738",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/us/security/advisories/VMSA-2017-0001.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data."
    },
    {
      "lang": "es",
      "value": "Airwatch Agent para Android contiene una vulnerabilidad que puede permitir a un dispositivo omitir la detección de root. La explotación con éxito de este problema puede resultar en que un dispositivo registrado tenga acceso sin restricciones a los datos y controles de seguridad locales de Airwatch."
    }
  ],
  "lastModified": "2026-06-17T01:19:30.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:airwatch_agent:-:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0212914-AA83-44A2-B521-F7F4A6D9522D"
            },
            {
              "criteria": "cpe:2.3:a:vmware:airwatch_inbox:-:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0018380C-249A-423E-9322-8B703395F9BF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}