CVE Vulnerabilities

CVE-2019-20772

Published: Apr 17, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August 2019).

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle7.0 (including)7.0 (including)
AndroidGoogle7.1 (including)7.1 (including)
AndroidGoogle7.2 (including)7.2 (including)
AndroidGoogle8.0 (including)8.0 (including)
AndroidGoogle8.1 (including)8.1 (including)
AndroidGoogle9.0 (including)9.0 (including)

References