Out of Bounds Read Vulnerability in MediaTek WLAN Software
CVE-2023-20730
4.4MEDIUM
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 6 June 2023
Summary
A vulnerability exists in MediaTek's WLAN software where a missing bounds check can result in an out of bounds read. This flaw could potentially allow local information disclosure, requiring system execution privileges for successful exploitation. Notably, user interaction is not needed to exploit this vulnerability, which increases the risk of unauthorized access to sensitive information. A fix is available under Patch ID ALPS07573552, addressing this critical gap in security.
Affected Version(s)
MT6985, MT7902, MT7921, MT8365, MT8518, MT8532 Android 13.0 / Yocto 3.1, 3.3, 4.0
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved