PT-2018-19008 · Google · Android
Published
2018-11-06
·
Updated
2019-10-03
·
CVE-2018-9438
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions 8.1
Description
The issue occurs when a device connects over WiFi VPN, potentially preventing it from receiving security updates due to incorrect checks. This could lead to a local denial of service of security updates without requiring additional execution privileges. User interaction is necessary for exploitation.
Recommendations
For Android version 8.1, ensure that devices are configured to receive security updates through alternative means when connected over WiFi VPN to mitigate the risk of denial of service for security updates.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android