PT-2021-13063 · Google · Android

Published

2021-03-10

·

Updated

2022-07-12

·

CVE-2021-0385

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android versions Android-11
Description: The issue allows for a possible connection to untrusted WiFi networks due to notification interaction above the lockscreen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations: For Android version Android-11, consider disabling notification interaction above the lockscreen until a patch is available to prevent potential exploitation. Restrict access to WiFi network settings to minimize the risk of connecting to untrusted networks.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-0385

Affected Products

Android