PT-2021-2463 · Google+1 · Android Kernel+1

Published

2021-03-01

·

Updated

2022-07-12

·

CVE-2021-0462

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a logic error in the NXP NFC firmware, which could lead to a local escalation of privilege. System execution privileges are needed for exploitation, and user interaction is not required. The vulnerability is associated with insecure management of privileges in the NFC component of the Android operating system, allowing an attacker to elevate their privileges.
Recommendations For Android kernel, apply the necessary security updates to fix the insecure firmware update issue. As a temporary workaround, consider restricting access to the NFC firmware to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01830
CVE-2021-0462

Affected Products

Android Kernel
Nxp Nfc