Local DoS via Input Validation in Android WifiConfigurationUtil
CVE-2023-21252 Published on October 6, 2023

In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD


Products Associated with CVE-2023-21252

Want to know whenever a new CVE is published for Google Android? stack.watch will email you.

 

Affected Versions

Google Android:

Exploit Probability

EPSS
0.04%
Percentile
10.81%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.