5.9
CVSSv3

CVE-2016-0818

Published: 12/03/2016 Updated: 28/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x prior to 4.4.4, 5.x prior to 5.1.1 LMY49H, and 6.x prior to 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle malicious users to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0

google android 5.1.1

google android 4.4.2

google android 4.4.1

google android 4.1

google android 4.0.4

google android 5.0.2

google android 5.0.1

google android 4.2.2

google android 4.2.1

google android 4.0.1

google android 4.0

google android 6.0.1

google android 5.0

google android 4.4.3

google android 4.2

google android 4.1.2

google android 5.1.0

google android 5.1

google android 4.4

google android 4.3.1

google android 4.3

google android 4.0.3

google android 4.0.2