Junglewise Threat Intelligence

CVE-2016-1920: Samsung KNOX shared certificate man-in-the-middle vulnerability

CVE-2016-1920 · Severity: medium · CVSS 5.5 · Published 2017-01-27

Technologies: Samsung Knox. Vendors: Samsung.

Executive brief

Samsung KNOX is a security framework designed to provide a secure environment for mobile devices. A vulnerability in version 1.0.0 allows a local user to intercept and modify encrypted traffic by exploiting how the system handles security certificates. This could allow an attacker to perform man-in-the-middle attacks, potentially compromising the integrity of data transmitted by the device.

Technical details

Samsung KNOX 1.0.0 suffers from an improper access control vulnerability (CWE-284) due to the use of a shared certificate store on the Android platform. A local attacker can exploit this by installing a malicious certificate and initiating a VPN service to intercept traffic. This configuration allows for man-in-the-middle (MitM) attacks against the secure container. The attack requires user interaction to install the certificate but can result in a high impact on data integrity. This issue is specific to the early implementation of the KNOX framework on Android.

Affected products

  • Samsung KNOX 1.0.0

Timeline

  • 2017-01-27: disclosed: NVD publication date

References

Related threats