Information Disclosure Vulnerability in DuraSpeed by MediaTek
CVE-2023-20825

5.5MEDIUM

Summary

In MediaTek's DuraSpeed, an information disclosure vulnerability exists due to a missing permission check. This flaw allows potential local information exposure without requiring elevated execution privileges, and it can be exploited without user interaction. Affected users should apply the necessary updates as indicated in the patch ID ALPS07951402 to mitigate the risks associated with this vulnerability.

Affected Version(s)

MT2713, MT6580, MT6735, MT6739, MT6761, MT6762, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8168, MT8175, MT8188, MT8195, MT8321, MT8365, MT8666, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8791T, MT8797 Android 12.0, 13.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.