peter bassill · operator
$ cve CVE-2019-16256 JSON

CVE-2019-16256 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 4.9% (pctl 92)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.95% — more likely to be exploited than 92% of all CVEs
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2019-09-12
Last modified2026-06-17

CISA KEV

NameSIMalliance Toolbox Browser Command Injection Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productSIMalliance / Toolbox Browser
Ransomware usenone reported

Affected (1)

VendorProduct
trustedconnectivityalliances\@t browser

References

→ the Explorer  ·  watch your stack  ·  NVD