CVE-2022-20195
published 2022-06-15CVE-2022-20195: In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service…
PriorityP418medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.16%
5.9th percentile
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-213172664
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | system_security | >= 12L:0 < 12L:2022-06-01 | 12L:2022-06-01 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c6vw-pfx6-wqr2: In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization
ghsa_unreviewed·2022-06-16
CVE-2022-20195 [MEDIUM] CWE-502 GHSA-c6vw-pfx6-wqr2: In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-213172664
OSV
CVE-2022-20195: In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization
osv·2022-06-01
CVE-2022-20195 CVE-2022-20195: In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-15
Published