Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 23 May 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensecurity
Opensecurity mobile Security Framework |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensecurity
Opensecurity mobile Security Framework |
|
| Metrics |
cvssV3_1
|
Wed, 12 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Local Privilege Escalation in MobSF | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-02-05T18:41:02.991Z
Updated: 2025-02-12T19:41:05.811Z
Reserved: 2025-01-23T17:11:35.840Z
Link: CVE-2025-24805
Updated: 2025-02-12T19:39:22.054Z
Status : Analyzed
Published: 2025-02-05T19:15:46.487
Modified: 2025-05-23T17:01:45.157
Link: CVE-2025-24805
No data.