PT-2015-2207 · Google · Android

Published

2015-10-01

·

Updated

2021-11-30

·

CVE-2015-3860

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 5.1.1 LMY48M
Description The issue is related to inadequate access control in the Lockscreen component of the Android operating system. This can be exploited by a local attacker to gain access to the system due to the lack of restrictions on password length, potentially causing the application to crash when a large number of characters is entered.
Recommendations For Android versions prior to 5.1.1 LMY48M, update to version 5.1.1 LMY48M or later to resolve the issue. As a temporary workaround, consider restricting access to the Lockscreen or using alternative security measures until the update can be applied.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11553
CVE-2015-3860

Affected Products

Android