CVE-2022-20034

MEDIUM

Preloader XFLASH - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.0009
EPSS Percentile 0.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-295
Status published
Products (1)
google/android 11.0
Published Feb 09, 2022
Tracked Since Feb 18, 2026