CVE-2023-32820Reachable Assertion in Google Android

Severity
7.5HIGHNVD
EPSS
0.4%
top 36.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2

Description

In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDgoogle/android11.0, 12.0, 13.0+2
NVDlinuxfoundation/yocto3.1, 3.3+1

🔴Vulnerability Details

2
CVEList
CVE-2023-32820: In wlan firmware, there is a possible firmware assertion due to improper input handling2023-10-02
GHSA
GHSA-x676-9gf4-jg53: In wlan firmware, there is a possible firmware assertion due to improper input handling2023-10-02

📋Vendor Advisories

1
Android
CVE-2023-32820: wlan firmware2023-10-01
CVE-2023-32820 — Reachable Assertion in Google Android | cvebase