CVE-2015-6613

Android < 5.1.1 LMY48X and 6.0 < 2015-11-01 - Command Injection via Bluetooth Debugging Port

Title source: llm
STIX 2.1

Description

Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24371736.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034049

Scores

EPSS 0.0063
EPSS Percentile 45.6%

Details

CWE
CWE-77
Status published
Products (2)
google/android 6.0
google/android 5.0 - 5.1.1
Published Nov 03, 2015
Tracked Since Feb 18, 2026