CVE-2016-2423
Last modified
CVE-2016-2423 is a vulnerability of currently unknown severity. server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26303187.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26303187.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 4.0 | |
| Android | 4.0.1 | |
| Android | 4.0.2 | |
| Android | 4.0.3 | |
| Android | 4.0.4 | |
| Android | 4.1 | |
| Android | 4.1.2 | |
| Android | 4.2 | |
| Android | 4.2.1 | |
| Android | 4.2.2 | |
| Android | 4.3 | |
| Android | 4.3.1 | |
| Android | 4.4 | |
| Android | 4.4.1 | |
| Android | 4.4.2 | |
| Android | 4.4.3 | |
| Android | 5.0 | |
| Android | 5.0.1 | |
| Android | 5.1 | |
| Android | 5.1.0 | |
| Android | 6.0 | |
| Android | 6.0.1 |
References
- http://source.android.com/security/bulletin/2016-04-02.htmlVendor Advisory
- http://source.android.com/security/bulletin/2016-04-02.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2423?
How severe is CVE-2016-2423?
How do I fix CVE-2016-2423?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-2417media/libmedia/IOMX.cpp in mediaserver in Android 4.x before…
- CVE-2016-2418media/libmedia/IOMX.cpp in mediaserver in Android 6.x before…
- CVE-2016-2419media/libmedia/IDrm.cpp in mediaserver in Android 6.x before…
- CVE-2016-2420rootdir/init.rc in Android 4.x before 4.4.4 does not ensure …
- CVE-2016-2421Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 20…
- CVE-2016-2422Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x…
- CVE-2016-2424server/content/SyncStorageEngine.java in SyncStorageEngine i…
- CVE-2016-2425mail/compose/ComposeActivity.java in AOSP Mail in Android 4.…
- CVE-2016-2426server/content/ContentService.java in the Framework componen…
- CVE-2016-2427The AES-GCM specification in RFC 5084, as used in Android 5.…
- CVE-2016-2428libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x b…
- CVE-2016-2429libFLAC/stream_decoder.c in mediaserver in Android 4.x befor…
Are you affected by CVE-2016-2423?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
