CVE-2022-20556
published 2022-12-16CVE-2022-20556: In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.15%
4.8th percentile
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246301667
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | packages_apps_settings | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 NetworkProviderSettings.java launchConfigNewNetworkFragment permission (A-246301667 / EUVD-2022-25816)
vuldb·2026-04-21·CVSS 3.3
CVE-2022-20556 [LOW] Google Android 13.0 NetworkProviderSettings.java launchConfigNewNetworkFragment permission (A-246301667 / EUVD-2022-25816)
A vulnerability was found in Google Android 13.0. It has been declared as critical. The impacted element is the function launchConfigNewNetworkFragment of the file NetworkProviderSettings.java. Executing a manipulation can lead to permission issues.
The identification of this vulnerability is CVE-2022-20556. The attack can only be executed locally. There is no exploit available.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-rxh4-q26c-4fv9: In launchConfigNewNetworkFragment of NetworkProviderSettings
ghsa_unreviewed·2022-12-20
CVE-2022-20556 [LOW] CWE-862 GHSA-rxh4-q26c-4fv9: In launchConfigNewNetworkFragment of NetworkProviderSettings
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246301667
OSV
CVE-2022-20556: In launchConfigNewNetworkFragment of NetworkProviderSettings
osv·2022-12-01
CVE-2022-20556 CVE-2022-20556: In launchConfigNewNetworkFragment of NetworkProviderSettings
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published