CVE-2023-21311
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Oct 30, 2023
Updated: Nov 6, 2023
CWE ID 863
Summary
CVE-2023-21311 is a vulnerability affecting the settings functionality of a specific software. It allows secondary users to bypass permissions and control private DNS settings. This issue does not require any user interaction or additional execution privileges, making local information disclosure possible. The vulnerability could potentially be exploited without the primary user's knowledge.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Android