Out of Bounds Read Vulnerability in WLAN by MediaTek
CVE-2023-20731

4.4MEDIUM

Summary

A vulnerability exists within WLAN due to a missing bounds check, allowing for a potential out of bounds read. This security flaw could facilitate local information disclosure, necessitating system execution privileges for exploitation. Notably, user interaction is not required, making it easier for attackers to exploit. Affected users are encouraged to apply available patches to mitigate this risk.

Affected Version(s)

MT6761, MT6762, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT7663, MT7668, MT7902, MT7921, MT8167, MT8167S, MT8173, MT8175, MT8195, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8666, MT8695, MT8781, MT8788 Android 12.0, 13.0 / Yocto 3.1,3.3,4.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.