CVE-2022-20423
published 2022-10-11CVE-2022-20423: In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a…
PriorityP420medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.24%
15.2th percentile
In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239842288References: Upstream kernel
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.18-1 (bookworm) | linux 5.16.18-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.16.18-1 | 5.16.18-1 |
| linux | linux_kernel | >= 0 < 5.16.18-1 | 5.16.18-1 |
| linux | linux_kernel | >= 0 < 5.16.18-1 | 5.16.18-1 |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv4.6MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2022-20423: USB
vendor_android·2022-10-01·CVSS 4.6
CVE-2022-20423 [MEDIUM] CVE-2022-20423: USB
Android Security Bulletin 2022-10-01
CVE: CVE-2022-20423
Severity: HIGH
Type: EoP
Component: USB
References: A-239842288
Upstream kernel
[2]
Debian
CVE-2022-20423: linux - In rndis_set_response of rndis.c, there is a possible out of bounds write due to...
vendor_debian·2022·CVSS 4.6
CVE-2022-20423 [MEDIUM] CVE-2022-20423: linux - In rndis_set_response of rndis.c, there is a possible out of bounds write due to...
In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239842288References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.16.18-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.16.18-1)
sid: resolved (fixed in 5.16.18-1)
trixie: resolved (fixed in 5.16.18-1)
VulDB
Google Android USB Device rndis.c rndis_set_response out-of-bounds write (A-239842288 / EUVD-2022-25683)
vuldb·2026-04-13·CVSS 4.6
CVE-2022-20423 [MEDIUM] Google Android USB Device rndis.c rndis_set_response out-of-bounds write (A-239842288 / EUVD-2022-25683)
A vulnerability was found in Google Android. It has been classified as critical. The impacted element is the function rndis_set_response of the file rndis.c of the component USB Device Handler. The manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2022-20423. The attack can only be performed from a local environment. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
VulDB
Google Android integer overflow (A-239842288 / EUVD-2022-25683)
vuldb·2026-04-13·CVSS 4.6
CVE-2022-20423 [MEDIUM] Google Android integer overflow (A-239842288 / EUVD-2022-25683)
A vulnerability was found in Google Android and classified as problematic. Affected by this issue is some unknown functionality. The manipulation results in integer overflow.
This vulnerability is cataloged as CVE-2022-20423. The attack must be initiated from a local position. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-9994-rx95-frv3: In rndis_set_response of rndis
ghsa_unreviewed·2022-10-12
CVE-2022-20423 [MEDIUM] CWE-190 GHSA-9994-rx95-frv3: In rndis_set_response of rndis
In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239842288References: Upstream kernel
OSV
CVE-2022-20423: In rndis_set_response of rndis
osv·2022-10-11·CVSS 4.6
CVE-2022-20423 [MEDIUM] CVE-2022-20423: In rndis_set_response of rndis
In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239842288References: Upstream kernel
OSV
CVE-2022-20423: In rndis_set_response of rndis
osv·2022-10-01
CVE-2022-20423 CVE-2022-20423: In rndis_set_response of rndis
In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published