CVE-2023-36621
Estado: ModificadaCrítica (9.1)—
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.11%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
Referencias
- https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/
- https://seclists.org/fulldisclosure/2023/Jul/12
- https://useboomerang.com/
- https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/
- https://seclists.org/fulldisclosure/2023/Jul/12
- https://useboomerang.com/
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-36621",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-36621",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-05T14:58:16.408830Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2023-11-03T04:15:21.083",
"references": [
{
"url": "https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://seclists.org/fulldisclosure/2023/Jul/12",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://useboomerang.com/",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://seclists.org/fulldisclosure/2023/Jul/12",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://useboomerang.com/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing."
},
{
"lang": "es",
"value": "Se descubrió un problema en la aplicación Boomerang Parental Control hasta la versión 13.83 para Android. El niño puede utilizar el Modo Seguro para eliminar temporalmente todas las restricciones o desinstalar la aplicación sin que los padres se den cuenta."
}
],
"lastModified": "2026-06-17T06:06:41.177",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nationaledtech:boomerang:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "089758F0-76D9-4112-BD0E-30126923EFE1",
"versionEndExcluding": "13.83"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}