Lucene search

K
osvGoogleOSV:ASB-A-159062405
HistoryOct 01, 2020 - 12:00 a.m.

Missing validation of package name in EuiccController#getEid

2020-10-0100:00:00
Google
osv.dev
11
euicccontroller
geteid
uiccaccessrule
missing validation
local information disclosure
eid data
no user interaction
software

EPSS

0

Percentile

5.1%

In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

0

Percentile

5.1%

Related for OSV:ASB-A-159062405