« Volver al listado

CVE-2016-10139

Estado: ModificadaAlta (7.8)—

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltration are com.adups.fota and com.adups.fota.sysoper. In the com.adups.fota.sysoper app's AndroidManifest.xml file, it sets the android:sharedUserId attribute to a value of android.uid.system which makes it execute as the system user, which is a very privileged user on the device. Therefore, the app executing as the system user has been granted a number of powerful permissions even though they are not present in the com.adups.fota.sysoper app's AndroidManifest.xml file.

Leer descripción completaMostrar menos

This app provides the com.adups.fota app access to the user's call log, text messages, and various device identifiers through the com.adups.fota.sysoper.provider.InfoProvider component. The com.adups.fota app uses timestamps when it runs and is eligible to exfiltrate the user's PII every 72 hours. If 72 hours have passed since the value of the timestamp, then the exfiltration will be triggered by the user plugging in the device to charge or when they leave or enter a wireless network. The exfiltration occurs in the background without any user interaction.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-10139",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-01-13T09:59:00.310",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/96858",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.kryptowire.com/adups_security_analysis.html",
      "tags": [
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html",
      "tags": [
        "Press/Media Coverage"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/96858",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kryptowire.com/adups_security_analysis.html",
      "tags": [
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html",
      "tags": [
        "Press/Media Coverage"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltration are com.adups.fota and com.adups.fota.sysoper. In the com.adups.fota.sysoper app's AndroidManifest.xml file, it sets the android:sharedUserId attribute to a value of android.uid.system which makes it execute as the system user, which is a very privileged user on the device. Therefore, the app executing as the system user has been granted a number of powerful permissions even though they are not present in the com.adups.fota.sysoper app's AndroidManifest.xml file. This app provides the com.adups.fota app access to the user's call log, text messages, and various device identifiers through the com.adups.fota.sysoper.provider.InfoProvider component. The com.adups.fota app uses timestamps when it runs and is eligible to exfiltrate the user's PII every 72 hours. If 72 hours have passed since the value of the timestamp, then the exfiltration will be triggered by the user plugging in the device to charge or when they leave or enter a wireless network. The exfiltration occurs in the background without any user interaction."
    },
    {
      "lang": "es",
      "value": "Se descubrió un problema en los dispositivos BLU R1 HD con software Shanghai Adups. Los dos nombres de paquetes implicados en la exfiltración son com.adups.fota y com.adups.fota.sysoper. En el archivo AndroidManifest.xml de la aplicación com.adups.fota.sysoper, establece el atributo android: sharedUserId en un valor de android.uid.system que lo hace ejecutar como el usuario del sistema, el cual es un usuario muy privilegiado en el dispositivo. Por lo tanto, se ha concedido a la aplicación que ejecuta como usuario del sistema una serie de permisos potentes aunque no estén presentes en el archivo AndroidManifest.xml de la aplicación com.adups.fota.sysoper. Esta aplicación proporciona el acceso de la aplicación com.adups.fota al registro de llamadas del usuario, mensajes de texto y varios identificadores de dispositivo a través del componente com.adups.fota.sysoper.provider.InfoProvider. La aplicación com.adups.fota utiliza marcas de tiempo cuando se ejecuta y es elegible para exfiltrar la PII del usuario cada 72 horas. Si han pasado 72 horas desde el valor de la marca de tiempo, entonces la exfiltración será activada por el usuario que conecta el dispositivo para cargar o cuando salen o entran en una red inalámbrica. La exfiltración se produce en el fondo sin ninguna interacción del usuario."
    }
  ],
  "lastModified": "2026-06-17T00:39:08.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adups:adups_fota:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8B2E488-EEE4-4C16-B1F6-BD5847A0DE1A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}