CVE-2021-0889
Last modified
CVE-2021-0889 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. EPSS estimates a 1.60% chance of exploitation in the next 30 days.
Description
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 8.1 | |
| Android | 9.0 | |
| Android | 10.0 | |
| Android | 11.0 | |
| Android | 12.0 |
References
- https://source.android.com/security/bulletin/2021-11-01Vendor Advisory
- https://source.android.com/security/bulletin/2021-11-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0889?
How severe is CVE-2021-0889?
How do I fix CVE-2021-0889?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0881In PVRSRVBridgeRGXKickCDM of the PowerVR kernel driver, a mi…7.8
- CVE-2021-0882In PVRSRVBridgeRGXKickSync of the PowerVR kernel driver, a m…7.8
- CVE-2021-0883In PVRSRVBridgeCacheOpQueue of the PowerVR kernel driver, a …7.8
- CVE-2021-0884In PVRSRVBridgePhysmemImportSparseDmaBuf of the PowerVR kern…7.8
- CVE-2021-0885In PVRSRVBridgeSyncPrimOpTake of the PowerVR kernel driver, …7.8
- CVE-2021-0887In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible le…5.5
- CVE-2021-0891An unprivileged app can trigger PowerVR driver to return an …7.5
- CVE-2021-0893In apusys, there is a possible memory corruption due to a us…6.7
- CVE-2021-0894In apusys, there is a possible out of bounds write due to a …6.7
- CVE-2021-0895In apusys, there is a possible out of bounds write due to a …6.7
- CVE-2021-0896In apusys, there is a possible out of bounds write due to a …6.7
- CVE-2021-0897In apusys, there is a possible out of bounds write due to a …6.7
Are you affected by CVE-2021-0889?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
