PT-2020-11801 · Google · Android

Published

2020-12-01

·

Updated

2021-07-21

·

CVE-2020-0460

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android version 11
Description A logic error in the createNameCredentialDialog of CertInstaller.java could lead to improperly installed certificates, resulting in remote information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version 11, consider restricting the installation of certificates until a patch is available to prevent potential remote information disclosure. As a temporary workaround, avoid using the createNameCredentialDialog function in CertInstaller.java until the issue is resolved.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-163413737
CVE-2020-0460

Affected Products

Android