CVE-2020-0469 is a local denial-of-service vulnerability affecting Android 11, stemming from a logic error in the addEscrowToken function of LockSettingsService.java that can lead to the loss of a synthetic password. Rated 5.5 MEDIUM, it requires no user interaction or additional privileges for exploitation, with an attack vector of local access and low complexity. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, it has garnered minimal community discussion and media coverage, with Samsung addressing it in their December 2020 updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.