In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258834033
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://source.android.com/security/bulletin/2023-06-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2023-06-15T00:00:00
Updated: 2024-08-02T09:28:25.658Z
Reserved: 2022-11-03T00:00:00
Link: CVE-2023-21115
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2023-06-15T19:15:09.467
Modified: 2023-06-22T20:53:57.617
Link: CVE-2023-21115
Redhat
No data.