CVE-2017-13215Improper Authentication in INC Android

Severity
7.8HIGHNVD
EPSS
0.1%
top 70.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateNov 2

Description

A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debianlinux/linux_kernel< 4.4.2-1+3
CVEListV5google_inc/androidAndroid kernel

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xpjw-vcgc-qx6p: A elevation of privilege vulnerability in the Upstream kernel skcipher2022-05-13
CVEList
CVE-2017-13215: A elevation of privilege vulnerability in the Upstream kernel skcipher2018-01-12
OSV
CVE-2017-13215: A elevation of privilege vulnerability in the Upstream kernel skcipher2018-01-12

📋Vendor Advisories

3
Red Hat
kernel: crypto: privilege escalation in skcipher_recvmsg function2018-01-02
Android
CVE-2017-13215: Skcipher2018-01-01
Debian
CVE-2017-13215: linux - A elevation of privilege vulnerability in the Upstream kernel skcipher. Product:...2017

📄Research Papers

1
arXiv
Partially-Observable Security Games for Automating Attack-Defense Analysis2022-11-02

💬Community

1
Bugzilla
CVE-2017-13215 kernel: crypto: privilege escalation in skcipher_recvmsg function2018-01-16
CVE-2017-13215 — Improper Authentication in INC Android | cvebase