Out of Bounds Read Vulnerability in MediaTek Products
CVE-2023-20844
4.2MEDIUM
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 4 September 2023
Summary
A vulnerability exists in the imgsys_cmdq component of certain MediaTek products, which may allow an attacker to read data outside the designated memory bounds. This issue arises from a lack of proper range checking and could potentially lead to local information disclosure. Successful exploitation requires user interaction and system execution privileges, highlighting the need for vigilance when using affected devices. MediaTek has provided a patch to mitigate this vulnerability, and users are encouraged to update their products promptly to safeguard against possible exploits.
Affected Version(s)
MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved