CVE-2023-20910
Published on: Not Yet Published
Last Modified on: 07/13/2023 12:15:00 AM UTC
Certain versions of Android from Google contain the following vulnerability:
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-20910 has been assigned by
secur[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Google - Android version = 13
- Affected Vendor/Software:
Google - Android version = 12L
- Affected Vendor/Software:
Google - Android version = 12
- Affected Vendor/Software:
Google - Android version = 11
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
8827591ae680c4d0bd0e373d4ca20cb35f53faa6 - platform/packages/modules/Wifi - Git at Google | android.googlesource.com text/html |
![]() |
Android Security Bulletin—July 2023 | Android Open Source Project | source.android.com text/html |
![]() |
d7df9d633c2726fa2bee8739c9ba274f300e1ea9 - platform/packages/modules/Wifi - Git at Google | android.googlesource.com text/html |
![]() |
Android Security Bulletin—March 2023 | Android Open Source Project | source.android.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Android | 11.0 | All | All | All | |
Operating System | Android | 12.0 | All | All | All | |
Operating System | Android | 12.1 | All | All | All | |
Operating System | Android | 13.0 | All | All | All |
- cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*:
- cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*:
- cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*:
- cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Google Android OS Could Allow for Remote Code Execution - PATCH: NOW | 2023-03-07 14:41:06 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Google Android OS Could Allow for Remote Code Execution - PATCH NOW | 2023-07-06 12:55:23 |