CVE-2022-20345: Command Injection
In l2cbleprocesssigcmd of l2cble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20345?
CVE-2022-20345 has a critical severity level due to its potential to allow remote code execution over Bluetooth.
How do I fix CVE-2022-20345?
To mitigate CVE-2022-20345, users should update their Android devices to the latest security patches provided by Google.
Which versions of Android are affected by CVE-2022-20345?
CVE-2022-20345 affects Android 12.0 and 12.1 specifically.
What type of vulnerability is CVE-2022-20345?
CVE-2022-20345 is an out of bounds write vulnerability that could lead to remote code execution.
Is user interaction required to exploit CVE-2022-20345?
No, exploitation of CVE-2022-20345 does not require any user interaction.