CVE-2024-34130

Severity
5.5MEDIUM
EPSS
0.0%
top 85.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5adobe/acrobat_mobile_sign_android24.4.2.33155
NVDadobe/acrobat_reader< 24.5.0.33694

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2pvg-pmc4-vr2x: Acrobat Mobile Sign Android versions 242024-06-13
CVEList
Acrobat Android : OverSecured Finding : Access to arbitrary* content providers via insecure Intent configuration2024-06-13
CVE-2024-34130 (MEDIUM CVSS 5.5) | Acrobat Mobile Sign Android version | cvebase.io