CVE-2023-21242

All FrameworksAndroidCWE-OtherCVE-2023-21242

CVE-2023-21242

State: PUBLISHED · Published: 2023-08-14 · Updated: 2024-10-09 · Assigner: google_android
Description
In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/21xxx/CVE-2023-21242.json