CVE-2017-0554Missing Authorization in INC Android

Severity
7.8HIGHNVD
EPSS
0.8%
top 26.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7
Latest updateMay 13

Description

An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33815946.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDgoogle/android28 versions+27
CVEListV5google_inc/android7 versions+6

🔴Vulnerability Details

1
GHSA
GHSA-w2w4-3x3r-9qm5: An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its pe2022-05-13

📋Vendor Advisories

1
Android
CVE-2017-0554: Android Security Bulletin 2017-04-01 CVE: CVE-2017-0554 Severity: MEDIUM Affected AOSP versions: 42017-04-01