PT-2018-19008 · Google · Android

Published

2018-11-06

·

Updated

2019-10-03

·

CVE-2018-9438

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.1
Description The issue occurs when a device connects over WiFi VPN, potentially preventing it from receiving security updates due to incorrect checks. This could lead to a local denial of service of security updates without requiring additional execution privileges. User interaction is necessary for exploitation.
Recommendations For Android version 8.1, ensure that devices are configured to receive security updates through alternative means when connected over WiFi VPN to mitigate the risk of denial of service for security updates.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-9438

Affected Products

Android