CVE-2022-20433Missing Authorization in Google Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateOct 12

Description

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221901

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-x9f9-fx28-38jm: There is an missing authorization issue in the system service2022-10-12
OSV
CVE-2022-20430: There is an missing authorization issue in the system service2022-10-01
OSV
CVE-2022-20430: There is an missing authorization issue in the system service2022-10-01

📋Vendor Advisories

1
Android
CVE-2022-20433: Telephony2022-10-01