CVE-2016-1920
published 2017-01-27CVE-2016-1920: Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a…
PriorityP417medium5.5CVSS 3.0
AVLACLPRNUIRSUCNIHAN
EPSS
0.38%
30.3th percentile
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | knox | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung KNOX 1.0.0 on Android Certificate access control
vuldb·2026-05-15·CVSS 5.5
CVE-2016-1920 [MEDIUM] Samsung KNOX 1.0.0 on Android Certificate access control
A vulnerability classified as problematic was found in Samsung KNOX 1.0.0 on Android. Affected by this vulnerability is an unknown functionality of the component Certificate Handler. The manipulation results in improper access controls.
This vulnerability is identified as CVE-2016-1920. The attack is only possible with local access. There is not any exploit available.
GHSA
GHSA-pqvr-gchh-537x: Samsung KNOX 1
ghsa_unreviewed·2022-05-14
CVE-2016-1920 [MEDIUM] CWE-284 GHSA-pqvr-gchh-537x: Samsung KNOX 1
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
No detection rules found.
No public exploits indexed.
2017-01-27
Published