Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/537339/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/537318/100/0/threaded | mailing list |