PT-2020-11402 · Google · Android
Published
2020-03-10
·
Updated
2021-07-21
·
CVE-2020-0035
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 8.0 through 9
Description
The issue concerns a missing permission check in the TelephonyProvider.java query, potentially allowing access to SIM card information. This could lead to local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations
For Android versions 8.0 through 9, apply the necessary permission checks to the TelephonyProvider.java query to prevent unauthorized access to SIM card information.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android