CVE-2016-4030 describes a vulnerability in several Samsung Galaxy S4, S6, and Note 3 models where the modem remains accessible via USB configuration 2 even when the device is locked. This flaw allows an attacker with physical access to make calls, send texts, or issue commands. Rated Medium severity (CVSS 6.8), it has a low attack complexity but high impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
g920fxxu2coh2CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s6_firmware:g920fxxu2coh2:*:*:*:*:*:*:* | ||
n9005xxugbob6CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_note_3_firmware:n9005xxugbob6:*:*:*:*:*:*:* | ||
i9192xxubnb1CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s4_mini_firmware:i9192xxubnb1:*:*:*:*:*:*:* | ||
i9195xxucol1CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s4_mini_lte_firmware:i9195xxucol1:*:*:*:*:*:*:* | ||
i9505xxuhoj2CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s4_firmware:i9505xxuhoj2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.