← KEV catalog
CISA known exploited vulnerability

CVE-2019-16256

SIMalliance Toolbox Browser Command Injection Vulnerability

SOURCE FACT

SIMalliance · Toolbox Browser

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2019-16256

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?