CVE-2017-18695: Google Android
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654 (January 2017).
Affected products
- Google Android: version 4.4 only; version 5.0 only; version 5.1 only; version 6.0 only; version 7.0 only
Published 2020-04-07. Last modified 2026-06-17.