PT-2023-5280 · Google · Android

CVE-2023-35671

·

Publicado

2023-06-15

·

Atualizado

2024-09-26

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a logic error in the code of HostEmulationManager.java, specifically in the onHostEmulationData function. This error allows a general-purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode, leading to local information disclosure without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ASB-A-268038643
BDU:2023-05903
CVE-2023-35671

Produtos afetados

Android