Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q4r-5p5v-23xq

Опубликовано: 16 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-201660636

In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-201660636

EPSS

Процентиль: 91%
0.06369
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-201660636

CVSS3: 10
fstec
больше 3 лет назад

Уязвимость компонента startLegacyVpnPrivileged (Vpn.java) операционных систем Android, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 91%
0.06369
Низкий

9.8 Critical

CVSS3