CVE-2022-20129
Description
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-217934478
Related CPE's
CvssV3 impact
Could not find any metrics
CvssV2 impact
AccessComplexity | LOW |
ConfidentialityImpact | NONE |
AvailabilityImpact | COMPLETE |
IntegrityImpact | NONE |
BaseScore | 4.900000095367432 |
VectorString | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Version | 2.0 |
AccessVector | LOCAL |
Authentication | NONE |