8.8

CVE-2020-0022

Exploit

In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715

Data is provided by the National Vulnerability Database (NVD)
GoogleAndroid Version8.0
GoogleAndroid Version8.1
GoogleAndroid Version9.0
GoogleAndroid Version10.0
HuaweiMate 20 Firmware Version < 10.0.0.195\(c00e74r3p8\)
   HuaweiMate 20 Version-
HuaweiMate 20 Pro Firmware Version < 10.0.0.196\(c185e7r2p4\)
   HuaweiMate 20 Pro Version-
HuaweiMate 20 X Firmware Version < 10.0.0.195\(c00e74r2p8\)
   HuaweiMate 20 X Version-
HuaweiP Smart Firmware Version < 9.1.0.193\(c605e6r1p5t8\)
   HuaweiP Smart Version-
HuaweiP Smart 2019 Firmware Version < 10.0.0.180\(c185e3r4p1\)
   HuaweiP Smart 2019 Version-
HuaweiP20 Firmware Version < 10.0.0.162\(c00e156r1p4\)
   HuaweiP20 Version-
HuaweiP20 Pro Firmware Version < 10.0.0.162\(c00e156r1p4\)
   HuaweiP20 Pro Version-
HuaweiP30 Firmware Version < 10.0.0.190\(c432e22r2p5\)
   HuaweiP30 Version-
HuaweiP30 Pro Firmware Version < 10.0.0.195\(c00e85r2p8\)
   HuaweiP30 Pro Version-
HuaweiY6 2019 Firmware Version < 9.1.0.290\(c185e5r4p1\)
   HuaweiY6 2019 Version-
HuaweiY6 Pro 2019 Firmware Version < 9.1.0.290\(c636e5r3p1\)
   HuaweiY6 Pro 2019 Version-
HuaweiY9 2019 Firmware Version < 9.1.0.264\(c185e2r5p1t8\)
   HuaweiY9 2019 Version-
HuaweiNova 3 Firmware Version < 9.1.0.338\(c00e333r1p1t8\)
   HuaweiNova 3 Version-
HuaweiNova Lite 3 Firmware Version < 9.1.0.322\(c635e8r2p2\)
   HuaweiNova Lite 3 Version-
HuaweiHonor 8a Firmware Version < 9.1.0.291\(c185e3r4p1\)
   HuaweiHonor 8a Version-
HuaweiHonor 8x Firmware Version < 10.0.0.183\(c185e2r6p1\)
   HuaweiHonor 8x Version-
HuaweiHonor View 20 Firmware Version < 10.0.0.195\(c636e3r4p3\)
   HuaweiHonor View 20 Version-
HuaweiMate 30 Pro Firmware Version < 10.0.0.203\(c00e202r7p2\)
   HuaweiMate 30 Pro Version-
HuaweiMate 30 Firmware Version < 10.0.0.203\(c00e202r7p2\)
   HuaweiMate 30 Version-
HuaweiMate 30 Pro 5g Firmware Version < 10.0.0.203\(c00e202r7p2\)
   HuaweiMate 30 Pro 5g Version-
HuaweiMate 30 5g Firmware Version < 10.0.0.203\(c00e202r7p2\)
   HuaweiMate 30 5g Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.73% 0.916
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-682 Incorrect Calculation

The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.