ID

VAR-202410-2074


CVE

CVE-2024-47027


TITLE

Google  of  Android  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-011352

DESCRIPTION

In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Google of Android Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Google Pixel is a smartphone produced by Google in the United States. Attackers can exploit this vulnerability to cause memory access

Trust: 2.16

sources: NVD: CVE-2024-47027 // JVNDB: JVNDB-2024-011352 // CNVD: CNVD-2024-45893

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-45893

AFFECTED PRODUCTS

vendor:googlemodel:androidscope:eqversion: -

Trust: 1.8

vendor:googlemodel:androidscope: - version: -

Trust: 0.8

vendor:googlemodel:pixelscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2024-45893 // JVNDB: JVNDB-2024-011352 // NVD: CVE-2024-47027

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-47027
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-47027
value: HIGH

Trust: 1.0

NVD: CVE-2024-47027
value: HIGH

Trust: 0.8

CNVD: CNVD-2024-45893
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-45893
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-47027
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-47027
baseSeverity: HIGH
baseScore: 7.4
vectorString: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.4
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2024-47027
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2024-45893 // JVNDB: JVNDB-2024-011352 // NVD: CVE-2024-47027 // NVD: CVE-2024-47027

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Path traversal (CWE-22) [ others ]

Trust: 0.8

problemtype: Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-011352 // NVD: CVE-2024-47027

PATCH

title:Patch for Google Pixel Input Validation Error Vulnerability (CNVD-2024-45893)url:https://www.cnvd.org.cn/patchInfo/show/611841

Trust: 0.6

sources: CNVD: CNVD-2024-45893

EXTERNAL IDS

db:NVDid:CVE-2024-47027

Trust: 3.2

db:JVNDBid:JVNDB-2024-011352

Trust: 0.8

db:CNVDid:CNVD-2024-45893

Trust: 0.6

sources: CNVD: CNVD-2024-45893 // JVNDB: JVNDB-2024-011352 // NVD: CVE-2024-47027

REFERENCES

url:https://source.android.com/security/bulletin/pixel/2024-10-01

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-47027

Trust: 1.4

sources: CNVD: CNVD-2024-45893 // JVNDB: JVNDB-2024-011352 // NVD: CVE-2024-47027

SOURCES

db:CNVDid:CNVD-2024-45893
db:JVNDBid:JVNDB-2024-011352
db:NVDid:CVE-2024-47027

LAST UPDATE DATE

2024-11-26T23:09:53.523000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-45893date:2024-11-25T00:00:00
db:JVNDBid:JVNDB-2024-011352date:2024-10-29T01:00:00
db:NVDid:CVE-2024-47027date:2024-10-28T17:58:46.217

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-45893date:2024-11-08T00:00:00
db:JVNDBid:JVNDB-2024-011352date:2024-10-29T00:00:00
db:NVDid:CVE-2024-47027date:2024-10-25T11:15:17.220