CVE-2023-36629
MEDIUMSt54-android-packages-apps-nfc - Out-of-Bounds Read
Title source: ruleDescription
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
References (3)
Core 3
Core References
Release Notes
https://github.com/STMicroelectronics/ST54-android-packages-apps-Nfc/releases/tag/130-20230215-23W07p0
Exploit, Press/Media Coverage
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/hunting-for-android-privilege-escalation-with-a-32-line-fuzzer/
Exploit, Third Party Advisory
https://www.trustwave.com/hubfs/Web/Library/Advisories_txt/TWSL2023-007_Xiaomi_Redmi_10sNote-1.txt
Scores
CVSS v3
5.5
EPSS
0.0004
EPSS Percentile
12.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-125
Status
published
Products (1)
st/st54-android-packages-apps-nfc
< 130-20230215-23w07p0
Published
Jan 09, 2024
Tracked Since
Feb 18, 2026