TROYANOSYVIRUS
Volver a CVEs

CVE-2023-20977

MEDIUM
4.4

Descripcion

In btm_ble_read_remote_features_complete of btm_ble_gap.cc, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if the firmware were compromised with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-254445952

Detalles CVE

Puntuacion CVSS v3.14.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado3/24/2023
Ultima modificacion2/25/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

google:android

Debilidades (CWE)

CWE-125CWE-125

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.