CVE-2020-0022
This could lead to remote code execution over Bluetooth with no additional execution privileges needed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.05% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-682
- Affected
- google/android · huawei/mate 20 firmware · huawei/mate 20 pro firmware · huawei/mate 20 x firmware · huawei/p smart firmware · huawei/p smart 2019 firmware · huawei/p20 firmware · huawei/p20 pro firmware · huawei/p30 firmware · huawei/p30 pro firmware · huawei/y6 2019 firmware · huawei/y6 pro 2019 firmware · huawei/y9 2019 firmware · huawei/nova 3 firmware · huawei/nova lite 3 firmware · huawei/honor 8a firmware · huawei/honor 8x firmware · huawei/honor view 20 firmware · huawei/mate 30 pro firmware · huawei/mate 30 firmware · +2 more
- Source
- security@android.com
References
- http://packetstormsecurity.com/files/156891/Android-Bluetooth-Remote-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Feb/10Mailing List, Third Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200513-03-smartphone-enThird Party Advisory
- https://source.android.com/security/bulletin/2020-02-01Patch, Vendor Advisory
- http://packetstormsecurity.com/files/156891/Android-Bluetooth-Remote-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Feb/10Mailing List, Third Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200513-03-smartphone-enThird Party Advisory
- https://source.android.com/security/bulletin/2020-02-01Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.