Out-of-Bounds Read Vulnerability in STMicroelectronics Android NFC Packages
CVE-2023-36629

5.5MEDIUM

Key Information:

Vendor
CVE Published:
9 January 2024

What is CVE-2023-36629?

The STMicroelectronics ST54 Android NFC package is affected by an out-of-bounds read vulnerability in versions prior to 130-20230215-23W07p0. This vulnerability could allow an attacker to exploit the affected application by reading sensitive data outside the normal boundaries of allocated memory, potentially leading to unauthorized access to information. It is essential for users to ensure their devices run the latest version of the ST54 Android NFC package to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.