CVE-2022-33699
LOWTelephonyUI <SMR Jul-2022 Release 1 - Info Disclosure
Title source: llmDescription
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
Scores
CVSS v3
2.0
EPSS
0.0002
EPSS Percentile
3.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
CWE-668
Status
published
Affected Products (3)
google/android
google/android
google/android
Timeline
Published
Jul 12, 2022
Tracked Since
Feb 18, 2026