CVE-2023-20941 - CERT CVE
ID CVE-2023-20941
Sažetak In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264029575References: Upstream kernel
Reference
CVSS
Base: 6.6
Impact: 5.9
Exploitability:0.7
Pristup
VektorSloženostAutentikacija
PHYSICAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 05-02-2025 - 19:15
Objavljeno 19-04-2023 - 20:15