CVE-2016-3888 Information
Feb 14, 2021
cve
Description
internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4 5.0.x before 5.0.2 5.1.x before 5.1.1 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and send premium SMS messages during the Setup Wizard provisioning stage via unspecified vectors aka internal bug 29420123.
CVSS Vector
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Reference
http://source.android.com/security/bulletin/2016-09-01.html http://www.securityfocus.com/bid/92857 http://www.securitytracker.com/id/1036763 https://android.googlesource.com/platform/frameworks/opt/telephony/+/b8d1aee993dcc565e6576b2f2439a8f5a507cff6
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
2.1
Share on: