In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258834033
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://source.android.com/security/bulletin/2023-06-01 |
History
Wed, 18 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2023-06-15T00:00:00
Updated: 2024-12-18T18:52:11.182Z
Reserved: 2022-11-03T00:00:00
Link: CVE-2023-21115
Vulnrichment
Updated: 2024-08-02T09:28:25.658Z
NVD
Status : Modified
Published: 2023-06-15T19:15:09.467
Modified: 2024-11-21T07:42:11.600
Link: CVE-2023-21115
Redhat
No data.