CVE-2019-16256 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 4.9% (pctl 92)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.95% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2019-09-12 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | SIMalliance Toolbox Browser Command Injection Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | SIMalliance / Toolbox Browser |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| trustedconnectivityalliance | s\@t browser |
References
→ the Explorer · watch your stack · NVD