CVE-2017-4896 is a low-severity vulnerability affecting Airwatch Inbox for Android, where a rooted device could decrypt local application data, potentially leading to unauthorized disclosure of confidential information. The attack requires local access to a rooted device with low privileges and no user interaction. While the CVSS score is low (3.8), indicating limited impact, there is no evidence of active exploitation, public exploit code, or significant community discussion beyond a single mention and media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_agent:-:*:*:*:*:android:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_inbox:-:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.