PT-2022-14429 · Google · Android

Published

2022-06-15

·

Updated

2023-08-08

·

CVE-2022-20200

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-12L
Description The issue is related to a possible leak of hotspot state due to a missing permission check in the updateApState function of SoftApManager.java. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android versions Android-12L, apply the necessary patch or update to fix the missing permission check in the updateApState function of SoftApManager.java. As a temporary workaround, consider restricting access to the SoftApManager functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-20200

Affected Products

Android