Lucene search

K
nvd[email protected]NVD:CVE-2022-20469
HistoryDec 13, 2022 - 4:15 p.m.

CVE-2022-20469

2022-12-1316:15:15
CWE-787
web.nvd.nist.gov
2
avct_lcb_msg_asmbl
avct_lcb_act.cc
out of bounds write
bluetooth privilege escalation
android-10
android-11
android-12
android-12l
android-13
a-230867224

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.6%

In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230867224

Affected configurations

NVD
Node
googleandroidMatch10.0
OR
googleandroidMatch11.0
OR
googleandroidMatch12.0
OR
googleandroidMatch12.1
OR
googleandroidMatch13.0

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.6%

Related for NVD:CVE-2022-20469