CVE-2017-0554 — Missing Authorization in INC Android
Severity
7.8HIGHNVD
EPSS
0.8%
top 26.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 7
Latest updateMay 13
Description
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33815946.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages3 packages
🔴Vulnerability Details
1GHSA▶
GHSA-w2w4-3x3r-9qm5: An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its pe↗2022-05-13
📋Vendor Advisories
1Android▶
CVE-2017-0554: Android Security Bulletin 2017-04-01
CVE: CVE-2017-0554
Severity: MEDIUM
Affected AOSP versions: 4↗2017-04-01