CVE-2013-6272
Last modified
CVE-2013-6272 is a vulnerability of currently unknown severity. The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | >= 4.1.1, <= 4.4.2 |
References
- http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2014/Jul/13Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68415Third Party Advisory, VDB Entry
- https://curesec.com/blog/article/blog/35.htmlExploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94423Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2014/Jul/13Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68415Third Party Advisory, VDB Entry
- https://curesec.com/blog/article/blog/35.htmlExploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94423Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-6272?
How severe is CVE-2013-6272?
How do I fix CVE-2013-6272?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-6263Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-6264Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-6265Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-6266Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-6267Multiple cross-site scripting (XSS) vulnerabilities in Claro…
- CVE-2013-6271Android 4.0 through 4.3 allows attackers to bypass intended …
- CVE-2013-6275Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.…6.5
- CVE-2013-6276QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entrie…9.8
- CVE-2013-6277QNAP VioCard 300 has hardcoded RSA private keys.7.5
- CVE-2013-6280Cross-site scripting (XSS) vulnerability in Social Sharing T…
- CVE-2013-6281Cross-site scripting (XSS) vulnerability in codebase/spreads…
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux…8.8
Are you affected by CVE-2013-6272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
