VDB
CVE-2021-1905
CVE-2021-1905
PUBLISHED
KEV
CVSS 8.399999618530273 HIGH
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119041698
EPSS 0.76% · 73.6th percentile
Risk Scores
CVSS v3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.76%
73.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| qualcomm | fsm10055_firmware | |
| qualcomm | sd765g_firmware | |
| qualcomm | qpm4640_firmware | |
| qualcomm | smb1395_firmware | |
| qualcomm | sdxr2_5g_firmware | |
| qualcomm | pm8350bh_firmware | |
| qualcomm | qca6421_firmware | |
| qualcomm | qpa8802_firmware | |
| qualcomm | qpm2630_firmware | |
| qualcomm | smb1360_firmware | |
| qualcomm | pmk8002_firmware | |
| qualcomm | pmm8155au_firmware | |
| qualcomm | pm670l_firmware | |
| qualcomm | qet6105_firmware | |
| qualcomm | qpm8830_firmware | |
| qualcomm | wtr2955_firmware | |
| qualcomm | sm4125_firmware | |
| qualcomm | wcn3620_firmware | |
| qualcomm | sd855_firmware | |
| qualcomm | sd675_firmware |
…and 378 more
Timeline
- May 3, 2021 PoC Published
- May 4, 2021 CVE Published
- May 7, 2021 EPSS Score
- Jul 10, 2021 EPSS Score
- Nov 3, 2021 CISA KEV Added
- Nov 8, 2021 PoC Published
- Nov 11, 2021 EPSS Score
- Nov 20, 2021 PoC Published
- Jan 6, 2022 EPSS Score
- Mar 14, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 15, 2022 EPSS Score
References
- https://www.qualcomm.com/company/product-security/bulletins/may-2021-bulletin url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1905 url
- https://source.android.com/security/bulletin/pixel/2021-05-01 advisory
- https://source.android.com/security/bulletin/2021-05-01 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-1905 advisory