
Cloud Vulnerability DB
A community-led vulnerabilities database
In done of CaptivePortalLoginActivity.java of Android 11, there is a confused deputy vulnerability (CVE-2021-0383). This vulnerability could lead to local escalation of privilege in carrier settings with no additional execution privileges needed. User interaction is not needed for exploitation (MITRE).
The vulnerability exists in the done method of CaptivePortalLoginActivity.java component. It is classified as a confused deputy vulnerability, which is a type of privilege escalation flaw. The CVSS score for this vulnerability is 4.6, indicating medium severity (CISA).
This vulnerability could lead to local escalation of privilege specifically in carrier settings. The exploitation does not require additional execution privileges or user interaction, making it potentially dangerous for Android 11 systems (MITRE).
The vulnerability can be exploited without requiring any additional execution privileges or user interaction. This makes the vulnerability relatively straightforward to exploit by a local attacker (CISA).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."