Vulnerability Description
In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-122652057
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 9.0 |
References
- https://lists.apache.org/thread.html/r167dbc42ef7c59802c2ca1ac14735ef9cf687c2520
- https://lists.apache.org/thread.html/r2ddabd06d94b60cfb0141e4abb23201c628ab925e3
- https://lists.apache.org/thread.html/r30a139c165b3da6e0d5536434ab1550534011b1fdf
- https://lists.apache.org/thread.html/r4e1619cfefcd031fac62064a3858f5c9229eef907b
- https://lists.apache.org/thread.html/r77af3ac7c3bfbd5454546e13faf7aec21d627bdcf3
- https://lists.apache.org/thread.html/rc9e441c1576bdc4375d32526d5cf457226928e9c87
- https://lists.apache.org/thread.html/rcd37d9214b08067a2e8f2b5b4fd123a1f8cb600869
- https://lists.apache.org/thread.html/rf9abfc0223747a56694825c050cc6b66627a293a32
- https://lists.apache.org/thread.html/rfc0db1f3c375087e69a239f9284ded72d04fbb5584
- https://source.android.com/security/bulletin/2020-02-01PatchVendor Advisory
- https://lists.apache.org/thread.html/r167dbc42ef7c59802c2ca1ac14735ef9cf687c2520
- https://lists.apache.org/thread.html/r2ddabd06d94b60cfb0141e4abb23201c628ab925e3
- https://lists.apache.org/thread.html/r30a139c165b3da6e0d5536434ab1550534011b1fdf
- https://lists.apache.org/thread.html/r4e1619cfefcd031fac62064a3858f5c9229eef907b
- https://lists.apache.org/thread.html/r77af3ac7c3bfbd5454546e13faf7aec21d627bdcf3
FAQ
What is CVE-2020-0028?
CVE-2020-0028 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote information disclosure with no additional execution p...
How severe is CVE-2020-0028?
CVE-2020-0028 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-0028?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android.