SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-0403

In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature.

MEDIUM 6.7EPSS 0.15%

Does this matter?

Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.

Description

In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-131252923

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.15% probability · 5th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
google/android
Source
security@android.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.