ICS: Rockwell Automation GuardLogix/ControlLogix Vulnerability
August 19, 2024Iran-Linked APT42 Launches Cyberattacks at US Presidential Elections – Active IOCs
August 19, 2024ICS: Rockwell Automation GuardLogix/ControlLogix Vulnerability
August 19, 2024Iran-Linked APT42 Launches Cyberattacks at US Presidential Elections – Active IOCs
August 19, 2024Severity
High
Analysis Summary
CVE-2024-34742 CVSS:7.5
Google Android is vulnerable to a denial of service, caused by a logic error in the code in shouldWrite of OwnersData.java. By sending a specially crafted request, a local attacker could exploit this vulnerability to cause a denial of service.
CVE-2024-34727 CVSS:7.5
Google Android could allow a remote attacker to obtain sensitive information, caused by a heap buffer overflow in sdpu_compare_uuid_with_attr of sdp_utils.cc. By sending a specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.
Impact
- Denial of Service
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2024-34742
- CVE-2024-34727
Affected Vendors
Affected Products
- Google Android - 14
Remediation
Upgrade to the latest version of Android, available from the Google Website.