CVE-2020-0450
published 2020-11-10CVE-2020-0450: In rw_i93_sm_format of rw_i93.cc, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure over NFC…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.84%
53.6th percentile
In rw_i93_sm_format of rw_i93.cc, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-157650336
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | system_nfc | >= 10:0 < 10:2020-11-01 | 10:2020-11-01 |
| platform | system_nfc | >= 11-next:0 < 11-next:2020-11-01 | 11-next:2020-11-01 |
| platform | system_nfc | >= 11:0 < 11:2020-11-01 | 11:2020-11-01 |
| platform | system_nfc | >= 8.0:0 < 8.0:2020-11-01 | 8.0:2020-11-01 |
| platform | system_nfc | >= 8.1:0 < 8.1:2020-11-01 | 8.1:2020-11-01 |
| platform | system_nfc | >= 9:0 < 9:2020-11-01 | 9:2020-11-01 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2020-0450: Android Security Bulletin 2020-11-01
CVE: CVE-2020-0450
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-11-01·CVSS 6.5
CVE-2020-0450 [MEDIUM] CVE-2020-0450: Android Security Bulletin 2020-11-01
CVE: CVE-2020-0450
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-11-01
CVE: CVE-2020-0450
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10, 11
References: A-157650336
GHSA
GHSA-6mfv-842h-v848: In rw_i93_sm_format of rw_i93
ghsa_unreviewed·2022-05-24
CVE-2020-0450 [MEDIUM] CWE-665 GHSA-6mfv-842h-v848: In rw_i93_sm_format of rw_i93
In rw_i93_sm_format of rw_i93.cc, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-157650336
OSV
CVE-2020-0450: In rw_i93_sm_format of rw_i93
osv·2020-11-01
CVE-2020-0450 CVE-2020-0450: In rw_i93_sm_format of rw_i93
In rw_i93_sm_format of rw_i93.cc, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-10
Published