CVE-2022-24925Improper Input Validation in Mobile Devices

Severity
6.5MEDIUMNVD
CNA4.4
EPSS
0.0%
top 85.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateFeb 12

Description

Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devices-Android S(12)
NVDgoogle/android12.0

🔴Vulnerability Details

2
GHSA
GHSA-4hmm-767m-727p: Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servic2022-02-12
CVEList
CVE-2022-24925: Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servic2022-02-11
CVE-2022-24925 — Improper Input Validation | cvebase