Skip to content
COOEY

EXPOSURES › CVE-2024-29745

CVE-2024-29745

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-29745 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Android Pixel fastboot firmware leaks sensitive data during device unlocking and flashing, enabling unauthorized access to device secrets.

This information disclosure vulnerability in Android Pixel's fastboot firmware allows attackers to extract sensitive data during the unlocking and flashing process, posing a significant risk to device security and compliance. DIB organizations must ensure their Android devices are patched and avoid using unpatched fastboot firmware to prevent potential data exfiltration and unauthorized access.

Shame score — A known information disclosure vulnerability in fastboot firmware that was actively exploited but did not involve remote code execution or default credentials.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.