CVE-2016-3888 PUBLISHED CVSS 2.0999999046325684 LOW

internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka internal bug 29420123.

EPSS 0.03% · 7.7th percentile

Risk Scores

CVSS v3.0
2.0999999046325684
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.03%
7.7th percentile

Affected Products

VendorProductVersions
googleandroid7.0, 4.0, 4.0.1
n/an/an/a

Timeline

References

Open in Interactive Console →