Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-0052

Опубликовано: 10 мар. 2020
Источник: nvd
CVSS3: 4.3
CVSS2: 1.9
EPSS Низкий

Описание

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 1%
0.0001
Низкий

4.3 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-306

Связанные уязвимости

github
больше 3 лет назад

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479

EPSS

Процентиль: 1%
0.0001
Низкий

4.3 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-306