CVE-2021-0904
published 2021-12-15CVE-2021-0904: In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.13%
3.3th percentile
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pf4w-mhjv-g5wm: In SRAMROM, there is a possible permission bypass due to an insecure permission setting
ghsa_unreviewed·2021-12-16
CVE-2021-0904 [HIGH] CWE-276 GHSA-pf4w-mhjv-g5wm: In SRAMROM, there is a possible permission bypass due to an insecure permission setting
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-201779035
OSV
CVE-2021-0904: In SRAMROM, there is a possible permission bypass due to an insecure permission setting
osv·2021-12-01
CVE-2021-0904 CVE-2021-0904: In SRAMROM, there is a possible permission bypass due to an insecure permission setting
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2021-0904: SRAMROM
vendor_android·2021-12-01·CVSS 6.7
CVE-2021-0904 [MEDIUM] CVE-2021-0904: SRAMROM
Android Security Bulletin 2021-12-01
CVE: CVE-2021-0904
Severity: HIGH
Component: SRAMROM
References: A-201779035
M-ALPS06076938
*
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published