Out of Bounds Read Vulnerability in MediaTek Bluetooth Driver
CVE-2023-32810

4.4MEDIUM

Summary

A vulnerability exists in the MediaTek Bluetooth driver due to improper input validation, resulting in a potential out of bounds read condition. This flaw could allow attackers with system execution privileges to access sensitive information, thereby compromising user data. Notably, user interaction is not required for the exploitation of this vulnerability, highlighting the urgency for patching and awareness. Affected users should ensure they apply the necessary updates to mitigate the risks associated with this security issue.

Affected Version(s)

MT2713, MT5221, MT6833, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6890, MT6893, MT6895, MT6983, MT8167, MT8168, MT8173, MT8175, MT8185, MT8188, MT8188T, MT8195, MT8321, MT8365, MT8385, MT8518S, MT8532, MT8666, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 Android 12.0, 13.0 / RDK-B 22Q3 / Linux4.19 / Yocto 3.1, 3.3, 4.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.