CVE-2023-21103
Last modified
CVE-2023-21103 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-259064622. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-259064622
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 11.0 | |
| Android | 12.0 | |
| Android | 12.1 | |
| Android | 13.0 |
References
- https://source.android.com/security/bulletin/2023-05-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/2023-05-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-21103?
How severe is CVE-2023-21103?
How do I fix CVE-2023-21103?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-21098In multiple functions of AccountManagerService.java, there i…7.8
- CVE-2023-21099In multiple methods of PackageInstallerSession.java, there i…7.8
- CVE-2023-2110Improper path handling in Obsidian desktop before 1.2.8 on W…7.1
- CVE-2023-21100In inflate of inflate.c, there is a possible out of bounds w…7.8
- CVE-2023-21101In multiple functions of WVDrmPlugin.cpp, there is a possibl…7
- CVE-2023-21102In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a poss…7.8
- CVE-2023-21104In applySyncTransaction of WindowOrganizer.java, a missing p…5.5
- CVE-2023-21105In multiple functions of ChooserActivity.java, there is a po…5.5
- CVE-2023-21106In adreno_set_param of adreno_gpu.c, there is a possible mem…7.8
- CVE-2023-21107In retrieveAppEntry of NotificationAccessDetails.java, there…7.8
- CVE-2023-21108In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possi…8.8
- CVE-2023-21109In multiple places of AccessibilityService, there is a possi…7.8
Are you affected by CVE-2023-21103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
