CVE-2020-0119 - CERT CVE
ID CVE-2020-0119
Sažetak In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150500247
Reference
CVSS
Base: 5.4
Impact: 6.9
Exploitability:4.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:N/AC:H/Au:N/C:C/I:N/A:N
Zadnje važnije ažuriranje 15-06-2020 - 16:21
Objavljeno 10-06-2020 - 18:15