CVE-2019-20536

CRITICAL

Samsung Android N(7.1) O(8.x) P(9.0) - Incorrect Default Permissions in Firewall PermissionWhiteLists

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (5)
google/android 7.1
google/android 8.0
google/android 8.1
google/android 9.0
google/android 10.0
Published Mar 24, 2020
Tracked Since Feb 18, 2026