CVE-2016-3887 PUBLISHED CVSS 6.800000190734863 MEDIUM

providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce the DISALLOW_CONFIG_VPN setting, which allows attackers to bypass an intended always-on VPN state via a crafted application, aka internal bug 29899712.

EPSS 0.10% · 27.0th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
0.10%
27.0th percentile

Affected Products

VendorProductVersions
n/an/an/a
googleandroid7.0

Timeline

References

Open in Interactive Console →