In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-218679614
CVE-2022-20508 - High Severity Vulnerability
Library home page: https://android.googlesource.com/platform/packages/apps/Settings
Found in HEAD commit: 0f7b87a5519c28af2891be292f34afa57b9a8cc2
Found in base branch: master
In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-218679614
Publish Date: 2022-12-16
URL: CVE-2022-20508
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: https://android.googlesource.com/platform/packages/apps/Settings/+/1f0689f73ce1e1d266a35bc3cdfaf72a442048f6
Release Date: 2022-12-16
Fix Resolution: android-13.0.0_r16
Step up your Open Source Security Game with Mend here