CVE-2022-20022Google Android vulnerability

2 documents2 sources
Severity
6.5MEDIUMNVD
EPSS
0.8%
top 26.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 4
Latest updateJan 5

Description

In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD address as the currently connected BT host. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198578; Issue ID: ALPS06198578.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/android10.0, 11.0+1

🔴Vulnerability Details

1
GHSA
GHSA-r374-8jvq-gj6j: In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD addre2022-01-05
CVE-2022-20022 — Google Android vulnerability | cvebase