5.4
CVSSv2

CVE-2016-6723

Published: 25/11/2016 Updated: 07/03/2019
CVSS v2 Base Score: 5.4 | Impact Score: 6.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 481
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C

Vulnerability Summary

A denial of service vulnerability in Proxy Auto Config in Android 4.x prior to 4.4.4, 5.0.x prior to 5.0.2, 5.1.x prior to 5.1.1, 6.x prior to 2016-11-01, and 7.0 prior to 2016-11-01 could enable a remote malicious user to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Android ID: A-30100884.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 7.0

google android

Exploits

Android devices can be crashed forcing a halt and then a soft reboot by downloading a large proxy auto config (PAC) file when adjusting the Android networking settings This can also be exploited by an MITM attacker that can intercept and replace the PAC file However, the bug is mitigated by multiple factors and the likelihood of exploitation is l ...