CVE-2016-2423

MEDIUM

Google Android - Access Control

Title source: rule

Description

server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26303187.

Scores

CVSS v3 6.1
EPSS 0.0002
EPSS Percentile 3.8%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-264
Status draft

Affected Products (22)

google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
... and 7 more

Timeline

Published Apr 18, 2016
Tracked Since Feb 18, 2026