Bluebird com.bluebird.filemanagers
- 1.4.4
A vulnerability exists in the pre-loaded file manager application on Bluebird devices, specifically in version 1.4.4. The application exposes an unsecured AIDL-type service provider, 'com.bluebird.system.koreanpost.IsdcardRemoteService', which allows local attackers to bind to the service and gain system-level permissions to copy and delete arbitrary files from the device's storage.
Exploitation of this vulnerability allows for unauthorized copying and deletion of files on the device, with system-level permissions.
Users can downgrade to version 1.3.6, which is not vulnerable, as the vendor has reverted vulnerable versions to this earlier release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.