CVE-2020-0403 describes a local escalation of privilege vulnerability affecting the Android kernel, specifically within the FPC TrustZone fingerprint application. An exposed test feature allows for an invalid command handler, enabling an attacker with System execution privileges to elevate their access within the Trusted Execution Environment (TEE). This vulnerability has a CVSS score of 6.7 (Medium) due to its local attack vector and high impact on confidentiality, integrity, and availability, requiring high privileges but no user interaction for exploitation. While the EPSS score is very low, indicating a minimal likelihood of exploitation, there is no public exploit code available, and it has received no community discussion or media coverage, suggesting it is not actively exploited or widely known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.