Out of Bounds Write Vulnerability in V6 DA by MediaTek
CVE-2024-20143

6.6MEDIUM

Summary

In V6 DA by MediaTek, a vulnerability exists due to a lack of proper bounds checking, which can lead to an out of bounds write condition. This oversight may allow an attacker with physical access to the device to escalate privileges locally. The exploitation requires user interaction, adding a layer of complexity to the attack. To mitigate this issue, the user needs to apply the latest patch (Patch ID: ALPS09167056; Issue ID: MSV-2069) as advised by MediaTek.

Affected Version(s)

MT2737, MT6781, MT6789, MT6835, MT6855, MT6878, MT6879, MT6880, MT6886, MT6890, MT6895, MT6897, MT6980, MT6983, MT6985, MT6989, MT6990, MT8370, MT8390, MT8676 Android 12.0, 13.0, 14.0, 15.0 / openWRT 19.07, 21.02, 23.05 / Yocto 4.0 / RDK-B 22Q3, 24Q1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.