Vulnerability Details CVE-2016-2423
server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26303187.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 6.6
Products affected by CVE-2016-2423
-
cpe:2.3:o:google:android:4.0
-
cpe:2.3:o:google:android:4.0.1
-
cpe:2.3:o:google:android:4.0.2
-
cpe:2.3:o:google:android:4.0.3
-
cpe:2.3:o:google:android:4.0.4
-
cpe:2.3:o:google:android:4.1
-
cpe:2.3:o:google:android:4.1.2
-
cpe:2.3:o:google:android:4.2
-
cpe:2.3:o:google:android:4.2.1
-
cpe:2.3:o:google:android:4.2.2
-
cpe:2.3:o:google:android:4.3
-
cpe:2.3:o:google:android:4.3.1
-
cpe:2.3:o:google:android:4.4
-
cpe:2.3:o:google:android:4.4.1
-
cpe:2.3:o:google:android:4.4.2
-
cpe:2.3:o:google:android:4.4.3
-
cpe:2.3:o:google:android:5.0
-
cpe:2.3:o:google:android:5.0.1
-
cpe:2.3:o:google:android:5.1
-
cpe:2.3:o:google:android:5.1.0
-
cpe:2.3:o:google:android:6.0
-
cpe:2.3:o:google:android:6.0.1