Permissions, Privileges, and Access Controls in Google Android - CVE-2016-2423

 

Permissions, Privileges, and Access Controls in Google Android - CVE-2016-2423

Published: April 18, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40348
CSH Severity: Medium
CVSS v4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2423
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to #BASIC_IMPACT#.

server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26303187.


Affected software

Google Android

How to mitigate CVE-2016-2423

Install update from vendor's website.


External References

Related Security Bulletins