PT-2021-2463 · Google+1 · Android Kernel+1
Published
2021-03-01
·
Updated
2022-07-12
·
CVE-2021-0462
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to a logic error in the NXP NFC firmware, which could lead to a local escalation of privilege. System execution privileges are needed for exploitation, and user interaction is not required. The vulnerability is associated with insecure management of privileges in the NFC component of the Android operating system, allowing an attacker to elevate their privileges.
Recommendations
For Android kernel, apply the necessary security updates to fix the insecure firmware update issue.
As a temporary workaround, consider restricting access to the NFC firmware to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel
Nxp Nfc