Memory Corruption in Bluetooth Functionality of MediaTek Products
CVE-2022-20046

5.5MEDIUM

Key Information:

Vendor
MediaTek
Vendor
CVE Published:
9 February 2022

Summary

A vulnerability has been identified in the Bluetooth functionality of certain MediaTek devices, resulting from a logic error that can cause memory corruption. This issue allows local denial of service without requiring additional execution privileges or user interaction to exploit the flaw. Affected users are encouraged to apply the latest patches to mitigate any potential risks associated with this vulnerability.

Affected Version(s)

MT8167, MT8175, MT8183, MT8362A, MT8365, MT8385 Android 8.1, 9.0, 10.0, 11.0, 12.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.