← back
CVE-2022-20476

CVE-2022-20476

CVSS 5.5 MEDIUMEPSS 0.2%CWE-835
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Dec 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-240936919
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · Android

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →