CVE-2016-3917
published 2016-10-10CVE-2016-3917: The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.8th percentile
The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging lockscreen access, aka internal bug 30744668.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vc6-pxqc-7hmr: The fingerprint login feature in Android 6
ghsa_unreviewed·2022-05-17
CVE-2016-3917 [HIGH] GHSA-5vc6-pxqc-7hmr: The fingerprint login feature in Android 6
The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging lockscreen access, aka internal bug 30744668.
OSV
CVE-2016-3917: The fingerprint login feature in Android 6
osv·2016-10-10·CVSS 7.8
CVE-2016-3917 [HIGH] CVE-2016-3917: The fingerprint login feature in Android 6
The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging lockscreen access, aka internal bug 30744668.
Android
CVE-2016-3917: Android Security Bulletin 2016-10-01
CVE: CVE-2016-3917
Severity: HIGH
Affected AOSP versions: 6
vendor_android·2016-10-01·CVSS 7.8
CVE-2016-3917 [HIGH] CVE-2016-3917: Android Security Bulletin 2016-10-01
CVE: CVE-2016-3917
Severity: HIGH
Affected AOSP versions: 6
Android Security Bulletin 2016-10-01
CVE: CVE-2016-3917
Severity: HIGH
Affected AOSP versions: 6.0.1, 7.0
References: A-30744668
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.securityfocus.com/bid/93298https://android.googlesource.com/platform/frameworks/base/+/f5334952131afa835dd3f08601fb3bced7b781cdhttp://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.securityfocus.com/bid/93298https://android.googlesource.com/platform/frameworks/base/+/f5334952131afa835dd3f08601fb3bced7b781cd
2016-10-10
Published