CVE-2016-3888
published 2016-09-11CVE-2016-3888: internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01…
PriorityP46low2.1CVSS 3.0
AVPACLPRLUINSUCNILAN
EPSS
0.18%
7.2th percentile
internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka internal bug 29420123.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.02.1LOWCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g38-6846-pr4j: internal/telephony/SMSDispatcher
ghsa_unreviewed·2022-05-17
CVE-2016-3888 [LOW] GHSA-4g38-6846-pr4j: internal/telephony/SMSDispatcher
internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka internal bug 29420123.
Android
CVE-2016-3888: Android Security Bulletin 2016-09-01
CVE: CVE-2016-3888
Severity: MEDIUM
Affected AOSP versions: 4
vendor_android·2016-09-01·CVSS 2.1
CVE-2016-3888 [LOW] CVE-2016-3888: Android Security Bulletin 2016-09-01
CVE: CVE-2016-3888
Severity: MEDIUM
Affected AOSP versions: 4
Android Security Bulletin 2016-09-01
CVE: CVE-2016-3888
Severity: MEDIUM
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0
References: A-29420123
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-09-01.htmlhttp://www.securityfocus.com/bid/92857http://www.securitytracker.com/id/1036763https://android.googlesource.com/platform/frameworks/opt/telephony/+/b8d1aee993dcc565e6576b2f2439a8f5a507cff6http://source.android.com/security/bulletin/2016-09-01.htmlhttp://www.securityfocus.com/bid/92857http://www.securitytracker.com/id/1036763https://android.googlesource.com/platform/frameworks/opt/telephony/+/b8d1aee993dcc565e6576b2f2439a8f5a507cff6
2016-09-11
Published