10

CVE-2023-48418

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
    possible way to access adb before SUW completion due to an insecure default
    value. This could lead to local escalation of privilege with no additional
    execution privileges needed. User interaction is not needed for
    exploitation

Data is provided by the National Vulnerability Database (NVD)
GooglePixel Watch Firmware Version-
   GooglePixel Watch Version11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.176
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
dsap-vuln-management@google.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.