{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-40104","assignerOrgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","state":"PUBLISHED","assignerShortName":"google_android","dateReserved":"2023-08-09T02:29:31.021Z","datePublished":"2024-02-15T22:31:14.778Z","dateUpdated":"2024-08-02T18:24:55.545Z"},"containers":{"cna":{"providerMetadata":{"orgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","shortName":"google_android","dateUpdated":"2024-02-15T22:31:14.778Z"},"problemTypes":[{"descriptions":[{"lang":"en","description":"Information disclosure"}]}],"affected":[{"vendor":"Google","product":"Android","versions":[{"version":"13","status":"affected"},{"version":"12L","status":"affected"},{"version":"12","status":"affected"},{"version":"11","status":"affected"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation."}],"references":[{"url":"https://android.googlesource.com/platform/system/ca-certificates/+/91204b9fdbd77b3f27f94b73868607b2dccbfdad"},{"url":"https://source.android.com/security/bulletin/2023-11-01"}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-295","lang":"en","description":"CWE-295 Improper Certificate Validation"}]}],"affected":[{"vendor":"google","product":"android","cpes":["cpe:2.3:o:google:android:11.0:-:*:*:*:*:*:*","cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:*","cpe:2.3:o:google:android:12l:*:*:*:*:*:*:*","cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"11.0","status":"affected"},{"version":"12.0","status":"affected"},{"version":"12l","status":"affected"},{"version":"13.0","status":"affected"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-02-16T14:46:52.606970Z","id":"CVE-2023-40104","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-26T17:16:13.303Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T18:24:55.545Z"},"title":"CVE Program Container","references":[{"url":"https://android.googlesource.com/platform/system/ca-certificates/+/91204b9fdbd77b3f27f94b73868607b2dccbfdad","tags":["x_transferred"]},{"url":"https://source.android.com/security/bulletin/2023-11-01","tags":["x_transferred"]}]}]}}