VDB
GSD-2023-21242
GSD-2023-21242
PUBLISHED
In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 13 |
Timeline
- Nov 28, 2020 CVE Published