Out of Bounds Read Vulnerability in MediaTek Products
CVE-2023-20844

4.2MEDIUM

Key Information:

Vendor
MediaTek
Vendor
CVE Published:
4 September 2023

Summary

A vulnerability exists in the imgsys_cmdq component of certain MediaTek products, which may allow an attacker to read data outside the designated memory bounds. This issue arises from a lack of proper range checking and could potentially lead to local information disclosure. Successful exploitation requires user interaction and system execution privileges, highlighting the need for vigilance when using affected devices. MediaTek has provided a patch to mitigate this vulnerability, and users are encouraged to update their products promptly to safeguard against possible exploits.

Affected Version(s)

MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.