Executive brief
Samsung KNOX is a security framework designed to provide a secure environment for mobile devices. A vulnerability in version 1.0.0 allows a local user to intercept and modify encrypted traffic by exploiting how the system handles security certificates. This could allow an attacker to perform man-in-the-middle attacks, potentially compromising the integrity of data transmitted by the device.
Technical details
Samsung KNOX 1.0.0 suffers from an improper access control vulnerability (CWE-284) due to the use of a shared certificate store on the Android platform. A local attacker can exploit this by installing a malicious certificate and initiating a VPN service to intercept traffic. This configuration allows for man-in-the-middle (MitM) attacks against the secure container. The attack requires user interaction to install the certificate but can result in a high impact on data integrity. This issue is specific to the early implementation of the KNOX framework on Android.
Affected products
- Samsung KNOX 1.0.0
Timeline
- 2017-01-27: disclosed: NVD publication date