EXPOSURES › CVE-2019-16256
CVE-2019-16256
HIGH ⌖ ON CISA KEV · EXPLOITEDSIMalliance Toolbox Browser suffered a command injection flaw allowing attackers to execute arbitrary commands and steal device data.
A command injection vulnerability in SIMalliance Toolbox Browser allowed remote attackers to execute arbitrary commands, retrieve location and IMEI data, and potentially compromise the device. DIB organizations must ensure all mobile device management and browser software are patched and monitored for known KEV vulnerabilities to prevent similar supply-chain and device-level compromises.
Shame score — A command injection flaw in a widely used mobile device management tool allowed remote code execution and data theft, indicating a severe lack of input validation and patching discipline.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.
"SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message."