Shell Access Vulnerability in LG Devices
CVE-2022-23729

7.8HIGH

Key Information:

Vendor
Google
Vendor
CVE Published:
4 March 2022

Summary

This vulnerability allows unauthorized access to the shell of LG mobile devices when they are in their factory state. The issue arises because the authentication process typically required via Android Debug Bridge (adb) is bypassed, allowing potential attackers to exploit the device without proper permissions. As a result, sensitive data and system functionality can be compromised, highlighting the need for immediate attention and potential security patches from LG Electronics.

Affected Version(s)

LG mobile devices All up to Android version 11 (Except for Android 11 with mainline applied)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.