Search

Find a vulnerability

Search criteria

    8 vulnerabilities found for yocto by linuxfoundation

    CVE-2024-20089 (GCVE-0-2024-20089)

    Vulnerability from cvelistv5 – Published: 2024-09-02 02:07 – Updated: 2024-09-03 14:14
    VLAI
    Summary
    In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-03 14:13 UTC
    CWE
    • CWE-703 - Improper Check or Handling of Exceptional Conditions
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT6835, MT6878, MT6886, MT6897, MT6980, MT6985, MT6989, MT6990, MT8678, MT8775, MT8792, MT8796 Affected: Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3
    Create a notification for this product.
    mediatek mt6835 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6878 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6886 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6897 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6980 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6985 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6989 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6990 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8678 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8775 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8792 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8796 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 13.0
    Affected: 14.0
        cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:*
        cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 2.6
    Affected: 3.3
    Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6835",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6878",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6886",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6897",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6980",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6985",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6989",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6990",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8678",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8775",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8792",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8796",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "13.0"
                  },
                  {
                    "status": "affected",
                    "version": "14.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.6"
                  },
                  {
                    "status": "affected",
                    "version": "3.3"
                  },
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-20089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-03T14:13:06.564754Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-754",
                    "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-03T14:14:40.888Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT6835, MT6878, MT6886, MT6897, MT6980, MT6985, MT6989, MT6990, MT8678, MT8775, MT8792, MT8796",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-703",
                  "description": "CWE-703 Improper Check or Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-02T02:07:37.971Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2024"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2024-20089",
        "datePublished": "2024-09-02T02:07:37.971Z",
        "dateReserved": "2023-11-02T13:35:35.174Z",
        "dateUpdated": "2024-09-03T14:14:40.888Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-32811 (GCVE-0-2023-32811)

    Vulnerability from cvelistv5 – Published: 2023-09-04 02:28 – Updated: 2024-10-01 18:15
    VLAI
    Summary
    In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 18:07 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT8168, MT8175, MT8188, MT8195, MT8365, MT8666, MT8667, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 / Yocto 4.0
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek iot_yocto Affected: 23.0
        cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 13.0
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T15:25:37.093Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "iot_yocto",
                "vendor": "mediatek",
                "versions": [
                  {
                    "status": "affected",
                    "version": "23.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-32811",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T18:07:49.242266Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T18:15:59.375Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT8168, MT8175, MT8188, MT8195, MT8365, MT8666, MT8667, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 / Yocto 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-04T02:28:18.886Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-32811",
        "datePublished": "2023-09-04T02:28:18.886Z",
        "dateReserved": "2023-05-16T03:04:32.146Z",
        "dateUpdated": "2024-10-01T18:15:59.375Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20850 (GCVE-0-2023-20850)

    Vulnerability from cvelistv5 – Published: 2023-09-04 02:28 – Updated: 2024-10-01 17:38
    VLAI
    Summary
    In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 17:22 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Affected: Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek iot_yocto Affected: 23.0
        cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 11.0
        cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.1
        cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:41.111Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "iot_yocto",
                "vendor": "mediatek",
                "versions": [
                  {
                    "status": "affected",
                    "version": "23.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20850",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T17:22:21.552027Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T17:38:18.992Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-04T02:28:05.423Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20850",
        "datePublished": "2023-09-04T02:28:05.423Z",
        "dateReserved": "2022-10-28T02:03:23.696Z",
        "dateUpdated": "2024-10-01T17:38:18.992Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20849 (GCVE-0-2023-20849)

    Vulnerability from cvelistv5 – Published: 2023-09-04 02:28 – Updated: 2024-10-01 18:58
    VLAI
    Summary
    In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 18:46 UTC
    CWE
    • Elevation of Privilege
    • CWE-416 - Use After Free
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Affected: Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek iot_yocto Affected: 23.0
        cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 11.0
        cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.1
        cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:41.136Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:mediatek:iot_yocto:23.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "iot_yocto",
                "vendor": "mediatek",
                "versions": [
                  {
                    "status": "affected",
                    "version": "23.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20849",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T18:46:24.279622Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T18:58:38.274Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-04T02:28:03.822Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/September-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20849",
        "datePublished": "2023-09-04T02:28:03.822Z",
        "dateReserved": "2022-10-28T02:03:23.696Z",
        "dateUpdated": "2024-10-01T18:58:38.274Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20805 (GCVE-0-2023-20805)

    Vulnerability from cvelistv5 – Published: 2023-08-07 03:21 – Updated: 2024-10-22 15:13
    VLAI
    Summary
    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 14:59 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
    Create a notification for this product.
    mediatek mt2713 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8188 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8195 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8395 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8673 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:40.963Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt2713",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8188",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8195",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8395",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8673",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T14:59:23.445486Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T15:13:53.163Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T03:21:48.680Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20805",
        "datePublished": "2023-08-07T03:21:48.680Z",
        "dateReserved": "2022-10-28T02:03:23.671Z",
        "dateUpdated": "2024-10-22T15:13:53.163Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20804 (GCVE-0-2023-20804)

    Vulnerability from cvelistv5 – Published: 2023-08-07 03:21 – Updated: 2024-10-22 15:14
    VLAI
    Summary
    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 14:59 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
    Create a notification for this product.
    mediatek mt2713 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8188 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8195 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8395 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8673 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:40.978Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt2713",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8188",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8195",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8395",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8673",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20804",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T14:59:35.581255Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T15:14:08.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T03:21:46.656Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20804",
        "datePublished": "2023-08-07T03:21:46.656Z",
        "dateReserved": "2022-10-28T02:03:23.671Z",
        "dateUpdated": "2024-10-22T15:14:08.297Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20803 (GCVE-0-2023-20803)

    Vulnerability from cvelistv5 – Published: 2023-08-07 03:21 – Updated: 2024-10-22 15:14
    VLAI
    Summary
    In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 14:59 UTC
    CWE
    • Elevation of Privilege
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Affected: Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
    Create a notification for this product.
    mediatek mt2713 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8188 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8195 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8395 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8673 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:40.970Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt2713",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8188",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8195",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8395",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8673",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.7,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20803",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T14:59:45.539222Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T15:14:20.728Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Elevation of Privilege",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-07T03:21:44.390Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/August-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20803",
        "datePublished": "2023-08-07T03:21:44.390Z",
        "dateReserved": "2022-10-28T02:03:23.671Z",
        "dateUpdated": "2024-10-22T15:14:20.728Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-20677 (GCVE-0-2023-20677)

    Vulnerability from cvelistv5 – Published: 2023-04-06 00:00 – Updated: 2024-10-23 14:21
    VLAI
    Summary
    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588413; Issue ID: ALPS07588436.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-23 13:09 UTC
    CWE
    • Information Disclosure
    • CWE-125 - Out-of-bounds Read
    Impacted products
    Vendor Product Version
    MediaTek, Inc. MT5221, MT6781, MT6789, MT6833, MT6855, MT6877, MT6879, MT6895, MT6983, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8169, MT8175, MT8185, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8675, MT8695, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798 Affected: Android 11.0, 12.0, 13.0 / Yocto 3.1, 3.3, 4.0 / Linux-4.19 (for MT5221, MT7663, MT7668, MT7902 and MT7921 chipsets only)
    Create a notification for this product.
    mediatek mt5221 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt5221:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6781 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6789 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6833 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6855 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6877 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6879 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6895 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt6983 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7663 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7668 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7668:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7902 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt7921 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8167s Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8167s:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8168 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8169 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8169:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8175 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8175:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8185 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8185:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8362a Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8362a:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8365 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8385 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8518 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8518:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8532 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8532:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8675 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8695 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8695:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8766 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8768 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8771 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8781 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8786 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8788 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8789 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8789:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8791t Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8797 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
    Create a notification for this product.
    mediatek mt8798 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
    Create a notification for this product.
    google android Affected: 11.0
    Affected: 12.0
    Affected: 13.0
        cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
        cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    Create a notification for this product.
    linuxfoundation yocto Affected: 3.1
    Affected: 3.3
    Affected: 4.0
        cpe:2.3:a:linuxfoundation:yocto:3.1:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
        cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:14:39.893Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://corp.mediatek.com/product-security-bulletin/April-2023"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt5221:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt5221",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6781",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6789",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6833",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6855",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6877",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6879",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6895",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt6983",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7663",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7668:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7668",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7902",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt7921",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8167s:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8167s",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8168",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8169:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8169",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8175:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8175",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8185:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8185",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8362a:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8362a",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8365",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8385",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8518:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8518",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8532:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8532",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8675",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8695:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8695",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8766",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8768",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8771",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8781",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8786",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8788",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8789:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8789",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8791t",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8797",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mt8798",
                "vendor": "mediatek",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "android",
                "vendor": "google",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.0"
                  },
                  {
                    "status": "affected",
                    "version": "12.0"
                  },
                  {
                    "status": "affected",
                    "version": "13.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:linuxfoundation:yocto:3.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yocto",
                "vendor": "linuxfoundation",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.1"
                  },
                  {
                    "status": "affected",
                    "version": "3.3"
                  },
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "NONE",
                  "baseScore": 4.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-20677",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-23T13:09:16.177110Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-125",
                    "description": "CWE-125 Out-of-bounds Read",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-23T14:21:59.661Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MT5221, MT6781, MT6789, MT6833, MT6855, MT6877, MT6879, MT6895, MT6983, MT7663, MT7668, MT7902, MT7921, MT8167S, MT8168, MT8169, MT8175, MT8185, MT8362A, MT8365, MT8385, MT8518, MT8532, MT8675, MT8695, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798",
              "vendor": "MediaTek, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Android 11.0, 12.0, 13.0 / Yocto 3.1, 3.3, 4.0 / Linux-4.19 (for MT5221, MT7663, MT7668, MT7902 and MT7921 chipsets only)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588413; Issue ID: ALPS07588436."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-04-06T00:00:00.000Z",
            "orgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
            "shortName": "MediaTek"
          },
          "references": [
            {
              "url": "https://corp.mediatek.com/product-security-bulletin/April-2023"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ee979b05-11f8-4f25-a7e0-a1fa9c190374",
        "assignerShortName": "MediaTek",
        "cveId": "CVE-2023-20677",
        "datePublished": "2023-04-06T00:00:00.000Z",
        "dateReserved": "2022-10-28T00:00:00.000Z",
        "dateUpdated": "2024-10-23T14:21:59.661Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }