VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18654

CVE-2017-18654

Description

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certificate. The Samsung ID is SVE-2017-9659 (September 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

On Samsung mobile devices with M(6.0) and N(7.0, 7.1), an unauthenticated attacker can register a new security certificate, undermining device trust.

Vulnerability

On Samsung mobile devices running Android M(6.0) and N(7.0, 7.1) software, an unauthenticated attacker can register a new security certificate [1]. This flaw, identified as Samsung ID SVE-2017-9659 (September 2017), allows an untrusted certificate to be added to the device's trusted store without requiring authentication.

Exploitation

An attacker with no prior authentication can exploit this vulnerability by simply registering a new security certificate on the device. No special network position, user interaction, or race condition is required. The attacker can perform this action remotely or locally, as the device fails to enforce authentication for certificate registration.

Impact

Successful exploitation enables the attacker to install a malicious certificate trusted by the device. This undermines the device's trust model, potentially allowing the attacker to intercept or modify encrypted communications (man-in-the-middle), bypass certificate validation, and gain unauthorized access to sensitive data. The compromise affects the confidentiality and integrity of network communications.

Mitigation

Samsung addressed this vulnerability in a security update released in September 2017 [1]. Users should ensure their device is updated to the latest firmware that includes the fix. There is no known workaround; applying the security patch is the recommended mitigation. This CVE is not listed on the CISA KEV.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.