CVE-2022-20114
published 2022-05-10CVE-2022-20114: In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.8th percentile
In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211114016
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_services_telecomm | >= 10:0 < 10:2022-05-01 | 10:2022-05-01 |
| platform | packages_services_telecomm | >= 11:0 < 11:2022-05-01 | 11:2022-05-01 |
| platform | packages_services_telecomm | >= 12:0 < 12:2022-05-01 | 12:2022-05-01 |
| platform | packages_services_telecomm | >= 12L:0 < 12L:2022-05-01 | 12L:2022-05-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
D-Link Multiple Routers OS Command Injection Vulnerability
cisa·2022-09-08·CVSS 9.8
CVE-2018-6530 [CRITICAL] CWE-78 D-Link Multiple Routers OS Command Injection Vulnerability
Vulnerability: D-Link Multiple Routers OS Command Injection Vulnerability
Affected: D-Link Multiple Routers
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
Required Action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.
Notes: https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10105; https://nvd.nist.gov/vuln/detail/CVE-2018-6530
Remediation Due Date: 2022-09-29
Android
CVE-2022-20114: Android Security Bulletin 2022-05-01
CVE: CVE-2022-20114
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-211114016
vendor_android·2022-05-01·CVSS 7.8
CVE-2022-20114 [HIGH] CVE-2022-20114: Android Security Bulletin 2022-05-01
CVE: CVE-2022-20114
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-211114016
Android Security Bulletin 2022-05-01
CVE: CVE-2022-20114
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-211114016
GHSA
GHSA-5r79-xhch-gw42: In placeCall of TelecomManager
ghsa_unreviewed·2022-05-11
CVE-2022-20114 [HIGH] CWE-269 GHSA-5r79-xhch-gw42: In placeCall of TelecomManager
In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211114016
OSV
CVE-2022-20114: In placeCall of TelecomManager
osv·2022-05-01
CVE-2022-20114 CVE-2022-20114: In placeCall of TelecomManager
In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-10
Published