CVE-2020-11829 is a critical vulnerability affecting the com.coloros.codebook V2.0.0_5493e40_200722 component of Oppo ColorOS, allowing for privilege escalation due to dynamic loading of services in the backup and restore SDK. With a CVSS score of 9.8 (CRITICAL), this vulnerability can be exploited remotely over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is no evidence of active exploitation, its high severity warrants immediate attention. Community discussion and media coverage are minimal, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0_5493e40_200722CPE matchmatch criteria | cpe:2.3:o:oppo:coloros:2.0.0_5493e40_200722:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.