CVE-2022-20361
published 2022-08-10CVE-2022-20361: In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.92%
56.2th percentile
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | system_bt | >= 10:0 < 10:2022-08-01 | 10:2022-08-01 |
| platform | system_bt | >= 11:0 < 11:2022-08-01 | 11:2022-08-01 |
| platform | system_bt | >= 12:0 < 12:2022-08-01 | 12:2022-08-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-20361: Android Security Bulletin 2022-08-01
CVE: CVE-2022-20361
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-231161832
[2]
vendor_android·2022-08-01·CVSS 9.8
CVE-2022-20361 [CRITICAL] CVE-2022-20361: Android Security Bulletin 2022-08-01
CVE: CVE-2022-20361
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-231161832
[2]
Android Security Bulletin 2022-08-01
CVE: CVE-2022-20361
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-231161832
[2]
GHSA
GHSA-66vq-4grr-jm68: In btif_dm_auth_cmpl_evt of btif_dm
ghsa_unreviewed·2022-08-11
CVE-2022-20361 [CRITICAL] CWE-269 GHSA-66vq-4grr-jm68: In btif_dm_auth_cmpl_evt of btif_dm
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832
OSV
CVE-2022-20361: In btif_dm_auth_cmpl_evt of btif_dm
osv·2022-08-01
CVE-2022-20361 CVE-2022-20361: In btif_dm_auth_cmpl_evt of btif_dm
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-10
Published