Vulnerability CVE-2013-6272


Published: 2018-05-02

Description:
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.

See advisories in our WLB2 database:
Topic
Author
Date
High
Android OS Authorization Missing
Roberto Palear
08.07.2014

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Google -> Android 

 References:
http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html
http://seclists.org/fulldisclosure/2014/Jul/13
http://www.securityfocus.com/bid/68415
https://curesec.com/blog/article/blog/35.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/94423

Copyright 2024, cxsecurity.com

 

Back to Top