Out of Bounds Read Vulnerability in MediaTek WLAN
CVE-2023-20728

4.4MEDIUM

Summary

A vulnerability exists in MediaTek WLAN due to a missing bounds check that can result in out of bounds read. This flaw may allow an attacker to access sensitive local information without requiring user interaction. Exploitation necessitates system execution privileges, making it essential for users and administrators of MediaTek devices to apply available patches and mitigate potential risks.

Affected Version(s)

MT6781, MT6789, MT6833, MT6835, MT6855, MT6877, MT6879, MT6886, MT6895, MT6983, MT6985, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8175, MT8185, MT8195, MT8362A, MT8365, MT8385, MT8395, MT8518, MT8532, MT8673, MT8675, MT8695, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 Android 12.0, 13.0 / Yocto 3.1, 3.3, 4.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.