corp.mediatek.com
https://corp.mediatek.com/product-security-bulletin/April-2023 CVE-2023-20677
MEDIUM
Record summary
CVE-2023-20677 has a selected CVSS score of 4.4 (medium).
Description
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588413; Issue ID: ALPS07588436.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List
Affected products and versions
Showing 12 of 38| Product | Source | Version range | Status |
|---|---|---|---|
MT5221, MT6781, MT6789, MT6833, MT6855, MT6877, MT6879, MT6895, MT6983, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8169, MT8175, MT8185, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8675, MT8695, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798Browse MediaTek, Inc. / MT5221, MT6781, MT6789, MT6833, MT6855, MT6877, MT6879, MT6895, MT6983, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8169, MT8175, MT8185, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8675, MT8695, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798 | CVE List | Android 11.0, 12.0, 13.0 / Yocto 3.1, 3.3, 4.0 / Linux-4.19 (for MT5221, MT7663, MT7668, MT7902 and MT7921 chipsets only) | affected |
androidBrowse google / androidDefault status: unknown | CVE List | 11.0 | affected |
| 12.0 | affected | ||
| 13.0 | affected | ||
Default status: unknown | CVE List | 3.1 | affected |
| 3.3 | affected | ||
| 4.0 | affected | ||
mt5221Browse mediatek / mt5221Default status: unknown | CVE List | Through * | affected |
mt6781Browse mediatek / mt6781Default status: unknown | CVE List | Through * | affected |
mt6789Browse mediatek / mt6789Default status: unknown | CVE List | Through * | affected |
mt6833Browse mediatek / mt6833Default status: unknown | CVE List | Through * | affected |
mt6855Browse mediatek / mt6855Default status: unknown | CVE List | Through * | affected |
mt6877Browse mediatek / mt6877Default status: unknown | CVE List | Through * | affected |
mt6879Browse mediatek / mt6879Default status: unknown | CVE List | Through * | affected |
mt6895Browse mediatek / mt6895Default status: unknown | CVE List | Through * | affected |
mt6983Browse mediatek / mt6983Default status: unknown | CVE List | Through * | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-20677