CVE-2016-6725 — Improper Access Control in Google Android
Severity
9.8CRITICALNVD
EPSS
3.1%
top 13.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 25
Latest updateMay 17
Description
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-334h-3w5w-cxp2: A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary c↗2022-05-17
OSV▶
CVE-2016-6725: A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary c↗2016-11-25
📋Vendor Advisories
1Android▶
CVE-2016-6725: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6725
Severity: CRITICAL
References: A-30515053
QC-CR#1050970↗2016-11-01