CVE-2016-6725Improper Access Control in Google Android

Severity
9.8CRITICALNVD
EPSS
3.1%
top 13.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 17

Description

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5google_inc/androidKernel-3.10, Kernel-3.18+1

🔴Vulnerability Details

2
GHSA
GHSA-334h-3w5w-cxp2: A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary c2022-05-17
OSV
CVE-2016-6725: A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary c2016-11-25

📋Vendor Advisories

1
Android
CVE-2016-6725: Android Security Bulletin 2016-11-01 CVE: CVE-2016-6725 Severity: CRITICAL References: A-30515053 QC-CR#10509702016-11-01