Vulnerabilities > CVE-2017-0493 - Insecure Storage of Sensitive Information vulnerability in Google Android 7.0/7.1.0/7.1.1

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
google
CWE-922

Summary

An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32793550.

Vulnerable Configurations

Part Description Count
OS
Google
3

Common Weakness Enumeration (CWE)