CVE-2020-0437: Medium severity Google Android vulnerability
In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-162741784
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0437?
CVE-2020-0437 is classified as a denial of service vulnerability due to a missing permission check.
How do I fix CVE-2020-0437?
To fix CVE-2020-0437, update to the latest version of the Android operating system that includes the necessary security patches.
Which Android versions are affected by CVE-2020-0437?
CVE-2020-0437 affects Google Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
Can CVE-2020-0437 be exploited without user interaction?
Yes, CVE-2020-0437 can be exploited without user interaction, leading to a local denial of service situation.
What components of Android are involved in CVE-2020-0437?
CVE-2020-0437 involves the CellBroadcastReceiver component of Android, specifically its intent handlers.