Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20941

Опубликовано: 19 апр. 2023
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264029575References: Upstream kernel

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00026
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 6.6
ubuntu
почти 3 года назад

In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264029575References: Upstream kernel

CVSS3: 6.6
debian
почти 3 года назад

In acc_ctrlrequest_composite of f_accessory.c, there is a possible out ...

CVSS3: 6.6
github
почти 3 года назад

In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264029575References: Upstream kernel

CVSS3: 6.6
fstec
почти 3 года назад

Уязвимость функции composite_dev_prepare() в модуле drivers/usb/gadget/function/f_accessory.c драйвера файловой системы USBFS ядра операционной системы Android (Android Common Kernel), позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 7%
0.00026
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-787
CWE-787