In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258834033
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2023-06-01 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: google_android
Published: 2023-06-15T00:00:00
Updated: 2023-06-15T00:00:00
Reserved: 2022-11-03T00:00:00
Link: CVE-2023-21115
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-06-15T19:15:09.467
Modified: 2023-06-22T20:53:57.617
Link: CVE-2023-21115
JSON object: View
Redhat Information
No data.
CWE