CVE-2014-6602 describes a lock-screen bypass vulnerability affecting Microsoft Asha OS on the Nokia Asha 501 phone, specifically version 14.0.4. A physically proximate attacker can exploit this by tapping the SOS Option followed by the Green Call Option, gaining unauthorized access. This allows them to read or modify contact information and dial arbitrary numbers. The vulnerability has a CVSS score of 6.6, indicating high severity due to local access requirements and complete confidentiality and integrity impact. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, and it has received minimal community discussion and no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0.4CPE matchmatch criteria | cpe:2.3:a:microsoft:nokia_asha_501_software:14.0.4:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:microsoft:nokia_asha_501:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.