Lucene search

K
cveMicrosoftCVE-2021-40448
HistorySep 15, 2021 - 12:15 p.m.

CVE-2021-40448

2021-09-1512:15:16
microsoft
web.nvd.nist.gov
55
cve
2021
40448
microsoft
accessibility insights
android
information disclosure
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.009

Percentile

82.5%

Microsoft Accessibility Insights for Android Information Disclosure Vulnerability

Affected configurations

Nvd
Vulners
Node
microsoftaccessibility_insights_for_androidRange<2021.826.1
VendorProductVersionCPE
microsoftaccessibility_insights_for_android*cpe:2.3:a:microsoft:accessibility_insights_for_android:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "Accessibility Insights for Android",
    "cpes": [
      "cpe:2.3:a:microsoft:accessibility_insights_for_android:*:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "2021.0.0",
        "lessThan": "2021.826.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.009

Percentile

82.5%