nanopathi/packages_apps_Settings_CVE-2021-0586

CVE-2021-0434 (High) detected in Settingsandroid-10.0.0_r33, Settingsandroid-10.0.0_r33

mend-bolt-for-github opened this issue · 0 comments

CVE-2021-0434 - High Severity Vulnerability

Vulnerable Libraries - Settingsandroid-10.0.0_r33, Settingsandroid-10.0.0_r33

Vulnerability Details

In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-167403112

Publish Date: 2021-12-15

URL: CVE-2021-0434

CVSS 3 Score Details (7.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://source.android.com/security/bulletin/2021-11-01

Release Date: 2021-12-15

Fix Resolution: android-11.0.0_r43


Step up your Open Source Security Game with Mend here