CVE-2018-9381

In gatts_process_read_by_type_req of gatt_sr.c, there is a possibleinformation disclosure due to uninitialized data. This could lead to remoteinformation disclosure with no additional execution privileges needed. Userinteraction is not needed for exploitation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
google_androidCNA
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
googleandroid
8.1
𝑥
= Vulnerable software versions