CVE-2016-1919
published 2017-01-27CVE-2016-1919: Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge…
PriorityP416medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.44%
35.4th percentile
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | knox | <= 1.0 | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung KNOX 1.0 eCryptFS Key Generator cryptographic issue (Bug 135303)
vuldb·2026-05-15·CVSS 4.7
CVE-2016-1919 [MEDIUM] Samsung KNOX 1.0 eCryptFS Key Generator cryptographic issue (Bug 135303)
A vulnerability classified as critical has been found in Samsung KNOX 1.0. Affected is an unknown function of the component eCryptFS Key Generator. The manipulation leads to cryptographic issues.
This vulnerability is referenced as CVE-2016-1919. The attack can only be performed from a local environment. No exploit is available.
GHSA
GHSA-xjjc-8jjh-rwv3: Samsung KNOX 1
ghsa_unreviewed·2022-05-14
CVE-2016-1919 [MEDIUM] CWE-200 GHSA-xjjc-8jjh-rwv3: Samsung KNOX 1
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.
No detection rules found.
No public exploits indexed.
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
arXiv
Secure Containers in Android: the Samsung KNOX Case Study
arxiv_fulltext·2016-05-27
Secure Containers in Android: the Samsung KNOX Case Study
Secure Containers in Android: \ Samsung KNOX Case Study
Uri Kanonov
School of Computer Science
Tel Aviv University
[email protected]
Avishai Wool
School of Electrical Engineering
Tel Aviv University
[email protected]
### Abstract
Bring Your Own Device (BYOD) is a growing trend among enterprises, aiming to improve workers' mobility and productivity via their smartphones.
The threats and dangers posed by the smartphones to the enterprise are also ever-growing.
Such dangers can be mitigated by running the enterprise software inside a ``secure container'' on the smartphone.
In our work we present a systematic assessment of security critical areas in design and implementation of a secure container for Android
using reverse engineering and attacker-inspired methods.
We do this thro
http://lists.openwall.net/bugtraq/2016/01/17/2http://packetstormsecurity.com/files/135303/Samsung-KNOX-1.0-Weak-eCryptFS-Key-Generation.htmlhttp://www.securityfocus.com/archive/1/537319/100/0/threadedhttp://www.securityfocus.com/archive/1/537340/100/0/threadedhttp://lists.openwall.net/bugtraq/2016/01/17/2http://packetstormsecurity.com/files/135303/Samsung-KNOX-1.0-Weak-eCryptFS-Key-Generation.htmlhttp://www.securityfocus.com/archive/1/537319/100/0/threadedhttp://www.securityfocus.com/archive/1/537340/100/0/threaded
2017-01-27
Published