CVE-2020-0023
published 2020-02-13CVE-2020-0023: In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.7th percentile
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145130871
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
vendor_vmware·2020-10-20·CVSS 5.8
CVE-2020-3981 [MEDIUM] VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
VMSA-2020-0023: VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
OpenSLP as used in ESXi has a use-after-free issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995
Affected products: Fusion Pro, NSX-T, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware NSX, VMware Workstation, VMware vCenter Server, VMware vSphere, Workstation Player, Workstation Pro
Android
CVE-2020-0023: Android Security Bulletin 2020-02-01
CVE: CVE-2020-0023
Severity: CRITICAL
Type: ID
Affected AOSP versions: 10
References: A-145130871
vendor_android·2020-02-01·CVSS 5.5
CVE-2020-0023 [MEDIUM] CVE-2020-0023: Android Security Bulletin 2020-02-01
CVE: CVE-2020-0023
Severity: CRITICAL
Type: ID
Affected AOSP versions: 10
References: A-145130871
Android Security Bulletin 2020-02-01
CVE: CVE-2020-0023
Severity: CRITICAL
Type: ID
Affected AOSP versions: 10
References: A-145130871
GHSA
GHSA-r9qr-6c7p-fgqr: In setPhonebookAccessPermission of AdapterService
ghsa_unreviewed·2022-05-24
CVE-2020-0023 [MEDIUM] CWE-276 GHSA-r9qr-6c7p-fgqr: In setPhonebookAccessPermission of AdapterService
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145130871
No detection rules found.
2020-02-13
Published