CVE-2023-35677Missing Authorization in Packages Apps Settings

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11

Description

In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Androidplatform/packages_apps_settings13-next:013-next:2023-09-01+4
CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

🔴Vulnerability Details

3
GHSA
GHSA-6mqc-xv9m-7m85: In onCreate of DeviceAdminAdd2023-09-11
CVEList
CVE-2023-35677: In onCreate of DeviceAdminAdd2023-09-11
OSV
CVE-2023-35677: In onCreate of DeviceAdminAdd2023-09-01

📋Vendor Advisories

1
Android
CVE-2023-35677: Android Security Bulletin 2023-09-01 CVE: CVE-2023-35677 Severity: HIGH Type: DoS Affected AOSP versions: 11, 12, 12L, 13 References: A-2807934272023-09-01
CVE-2023-35677 — Missing Authorization | cvebase