PT-2020-10748 · Google · Android
Published
2020-04-17
·
Updated
2021-07-21
·
CVE-2019-20773
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LG mobile devices with Android OS versions 7.0 through 9.0
Description
An issue allows unprivileged applications to execute shell commands via the connectivity service.
Recommendations
For Android OS versions 7.0 through 9.0, consider restricting access to the connectivity service to prevent unprivileged applications from executing shell commands until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android