VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18648

CVE-2017-18648

Description

An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file read/write operations can occur in the locked state via a crafted MTP command. The Samsung ID is SVE-2017-10086 (November 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Samsung mobile devices (KK to N) allow arbitrary file read/write in locked state via crafted MTP command, enabling data access without authentication.

Vulnerability

An issue exists in Samsung mobile devices running Android versions KK (4.4.x), L (5.x), M (6.x), and N (7.x) that allows arbitrary file read and write operations while the device is locked. The vulnerability is triggered via a crafted MTP (Media Transfer Protocol) command. The Samsung ID for this issue is SVE-2017-10086, reported in November 2017.

Exploitation

An attacker with physical access to a locked device can send a specially crafted MTP command over USB. No authentication or user interaction is required beyond connecting the device to a computer. The attacker does not need to unlock the screen or bypass the lock screen.

Impact

Successful exploitation allows the attacker to read and write arbitrary files on the device's filesystem, including sensitive user data such as contacts, messages, photos, and application data. This compromises the confidentiality and integrity of all data stored on the device, bypassing the lock screen protection.

Mitigation

Samsung has not publicly disclosed a specific patch for this vulnerability in the available references. Users should ensure their devices are updated to the latest firmware version provided by Samsung. As of the publication date (April 2020), no workaround or fix details are available from the referenced source.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.