CVE-2021-0889
published 2021-12-15CVE-2021-0889: In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITW
Exploited in the wild
EPSS
1.60%
73.3th percentile
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0889: Android TV Remote Service
vendor_android·2021-11-01·CVSS 9.8
CVE-2021-0889 [CRITICAL] CVE-2021-0889: Android TV Remote Service
Android Security Bulletin 2021-11-01
CVE: CVE-2021-0889
Severity: CRITICAL
Type: RCE
Component: Android TV Remote Service
References: A-180745296
GHSA
GHSA-56fq-7jc4-6x2c: In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow
ghsa_unreviewed·2021-12-16
CVE-2021-0889 [CRITICAL] GHSA-56fq-7jc4-6x2c: In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296
OSV
CVE-2021-0889: In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow
osv·2021-11-01
CVE-2021-0889 CVE-2021-0889: In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published
Exploited in the wild