CVE-2017-13322 Details
Description
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
A denial-of-service vulnerability has been identified in the Android framework, specifically within the Phone Interface Manager component. The issue arises from a logic error that can prevent access to emergency services, leading to a local denial-of-service condition. This vulnerability affects several Android versions, including 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1. Notably, the vulnerability can be exploited without requiring additional execution privileges or user interaction.
Users can update their devices to the May 2018 security patch level to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://source.android.com/security/bulletin/pixel/2018-05-01 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-783 | Operator Precedence Logic Error | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 6.0 6.0.1 7.0 7.1.1 7.1.2 8.0 8.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Initial Analysis | [email protected] |
| Jan 17, 2025 | New CVE Received | [email protected] |