PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-0423 Google CVE debrief

CVE-2017-0423 is a moderate Android Bluetooth elevation-of-privilege issue that can affect document access on impacted devices, but only when a nearby attacker first chains a separate Bluetooth stack vulnerability. NVD rates the issue as AV:A/AC:H with high confidentiality impact, so it is best treated as a targeted, adjacency-based risk rather than a broad remote compromise.

Vendor
Google
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-08
Original CVE updated
2026-05-13
Advisory published
2017-02-08
Advisory updated
2026-05-13

Who should care

Android device owners and administrators, MDM/endpoint security teams, and organizations that rely on Bluetooth-enabled Android devices in managed or sensitive environments.

Technical summary

The NVD record and Google Android bulletin describe an elevation-of-privilege issue in Bluetooth affecting Android 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.1, with adjacent release variants also marked vulnerable in NVD's CPE data. The attack requires nearby access and exploitation of another Bluetooth stack vulnerability first. NVD assigns CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N and maps the issue to CWE-732.

Defensive priority

Medium; prioritize if you operate exposed Android fleets with Bluetooth enabled, especially where document access or device privacy is sensitive.

Recommended defensive actions

  • Review Android fleet coverage for the affected versions listed by NVD and the Android bulletin.
  • Apply the vendor guidance from the Android security bulletin referenced in the record.
  • Reduce Bluetooth exposure where operationally feasible, especially on devices that handle sensitive documents.
  • Monitor managed devices for OS update compliance and remove or replace unsupported Android builds.
  • Treat this as a chained Bluetooth risk and assess whether nearby attacker scenarios are relevant in your environment.

Evidence notes

The supplied corpus ties this CVE to Google/Android guidance and the NVD detail page. The Android bulletin referenced in the record is dated 2017-02-01, while the CVE itself was published in NVD/CVE on 2017-02-08. NVD's vector (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) supports the adjacency and high-complexity interpretation, and the enrichment provided here does not list any KEV entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-0423 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-0423

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-0423 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0423

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.