CVE-2016-6723 is a denial-of-service vulnerability in the Proxy Auto Config component of Android, affecting versions 4.x through 7.0 prior to their respective November 2016 security updates. A remote attacker could exploit this by using a specially crafted file to cause a device hang or reboot. This vulnerability is rated Medium severity with a CVSS score of 4.7, indicating a local attack vector with high attack complexity, requiring user interaction and an uncommon device configuration to achieve high availability impact. There is no evidence of active exploitation, nor are there known public exploits or Metasploit modules available. Community discussion and media coverage are minimal, suggesting low overall attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, < 4.4.4CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
>= 5.1, < 5.1.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
>= 6.0, <= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.