CVE-2012-2217 - CVE House
Back to Database
Status published Medium CVE-2012-2217

The HTC IQRD service for Android on the HTC EVO...

Vulnerability Description

The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2217

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

evo 4g software, evo 4g, evo design 4g software, evo design 4g, shift 4g software, shift 4g, evo 3d software, evo 3d, evo view 4g software, evo view 4g, vivid software, vivid, hero software, hero
Vulnerable Versions:
0, 1.32.651.1, 1.47.651.1, 3.26.651.6, 3.29.651.5, 3.30.651.2, 3.30.651.3, 3.70.651.1, 4.22.651.2, 4.24.651.1, 4.53.651.1, gri40, 1.19.651.0, 1.17.651.1, 2.75.651.4, 2.75.651.5, 1.11.651.3, 1.13.651.7, 2.08.651.2, 1.22.651.1, 1.29.651.1, 1.56.651.2, 2.27.651.5, 2.27.651.6, 2.31.651.7, 2.32.651.2

Timeline

Official Publish: May 1st, 2012
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.