PT-2018-19008 · Google · Android

Publicado

2018-11-06

·

Atualizado

2019-10-03

·

CVE-2018-9438

CVSS v3.1

5.0

Média

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.1
Description The issue occurs when a device connects over WiFi VPN, potentially preventing it from receiving security updates due to incorrect checks. This could lead to a local denial of service of security updates without requiring additional execution privileges. User interaction is necessary for exploitation.
Recommendations For Android version 8.1, ensure that devices are configured to receive security updates through alternative means when connected over WiFi VPN to mitigate the risk of denial of service for security updates.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-9438

Produtos afetados

Android