CVE Vulnerabilities

CVE-2022-28782

Improper Protection of Alternate Path

Published: May 03, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Affected Software

Name Vendor Start Version End Version
Android Google 11.0 (including) 11.0 (including)
Android Google 12.0 (including) 12.0 (including)

Potential Mitigations

References