Vulnerabilities > CVE-2018-21047 - Missing Authorization vulnerability in Google Android 8.0/8.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
google
CWE-862

Summary

An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins before the Setup Wizard finishes. The Samsung ID is SVE-2018-12894 (November 2018).

Vulnerable Configurations

Part Description Count
OS
Google
2

Common Weakness Enumeration (CWE)