CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1 and 5.0.2 does not properly handle exceptions, which allows remote attackers to cause a denial of service (reboot) via a crafted 802.11 probe response frame.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 6.40% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- google/android
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/130107/Android-WiFi-Direct-Denial-Of-Service.htmlExploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jan/104Exploit, Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/534544/100/0/threaded
- http://www.securityfocus.com/bid/72311Third Party Advisory, VDB Entry
- https://www.coresecurity.com/advisories/android-wifi-direct-denial-serviceExploit, Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/35913/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/130107/Android-WiFi-Direct-Denial-Of-Service.htmlExploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jan/104Exploit, Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/534544/100/0/threaded
- http://www.securityfocus.com/bid/72311Third Party Advisory, VDB Entry
- https://www.coresecurity.com/advisories/android-wifi-direct-denial-serviceExploit, Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/35913/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.