PT-2020-11480 · Google · Android

Published

2020-06-10

·

Updated

2020-06-15

·

CVE-2020-0119

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-10
Description The issue is related to a possible man in the middle attack due to improper certificate validation in the addOrUpdateNetworkInternal and related functions of WifiConfigManager.java. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android version Android-10, consider disabling the addOrUpdateNetworkInternal function in WifiConfigManager.java as a temporary workaround until a patch is available. Restrict access to Wi-Fi networks to minimize the risk of exploitation. Avoid using untrusted Wi-Fi networks until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0119

Affected Products

Android