Lucene search

K
cveGoogle_androidCVE-2020-0069
HistoryMar 10, 2020 - 8:15 p.m.

CVE-2020-0069

2020-03-1020:15:21
CWE-787
google_android
web.nvd.nist.gov
929
In Wild
2
cve-2020-0069
mediatek command queue driver
out of bounds write
local privilege escalation
android
kernel
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.6%

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

Affected configurations

Nvd
Node
googleandroidMatch-
Node
huaweiberkeley-l09_firmwareRange<10.0.0.177\(c10e3r1p4\)
AND
huaweiberkeley-l09Match-
Node
huaweicolumbia-al10b_firmwareRange<10.0.0.178\(c00e178r1p4\)
AND
huaweicolumbia-al10bMatch-
Node
huaweicolumbia-l29d_firmwareRange<10.0.0.177\(c10e4r1p4\)
AND
huaweicolumbia-l29dMatch-
Node
huaweicolumbia-tl00b_firmwareRange<10.0.0.178\(c01e178r1p4\)
AND
huaweicolumbia-tl00bMatch-
Node
huaweicolumbia-tl00d_firmwareRange<10.0.0.178\(c01e178r1p4\)
AND
huaweicolumbia-tl00dMatch-
Node
huaweicornell-al00a_firmwareRange<9.1.0.340\(c00e333r1p1t8\)
AND
huaweicornell-al00aMatch-
Node
huaweicornell-tl10b_firmwareRange<9.1.0.340\(c01e333r1p1t8\)
AND
huaweicornell-tl10bMatch-
Node
huaweidura-al00a_firmwareRange<1.0.0.190\(c00\)
AND
huaweidura-al00aMatch-
Node
huaweihonor_20_pro_firmwareRange<10.0.0.194\(c636e3r3p1\)
AND
huaweihonor_20_proMatch-
Node
huaweiy6_2019_firmwareRange<9.1.0.290\(c185e5r4p1\)
AND
huaweiy6_2019Match-
Node
huaweinova_3_firmwareRange<9.1.0.338\(c00e333r1p1t8\)
AND
huaweinova_3Match-
Node
huaweinova_4_firmwareRange<10.0.0.160\(c01e32r2p4\)
AND
huaweinova_4Match-
Node
huaweihonor_8a_firmwareRange<9.1.0.291\(c185e3r4p1\)
AND
huaweihonor_8aMatch-
Node
huaweihonor_view_20_firmwareRange<10.0.0.198\(c432e10r3p4\)
AND
huaweihonor_view_20Match-
Node
huaweijakarta-al00a_firmwareRange<9.1.0.251\(c00e106r2p2\)
AND
huaweijakarta-al00aMatch-
Node
huaweikatyusha-al00a_firmwareRange<9.1.0.146\(c00e131r2p2\)
AND
huaweikatyusha-al00aMatch-
Node
huaweikatyusha-al10a_firmwareRange<9.1.0.160\(c00e150r1p7\)
AND
huaweikatyusha-al10aMatch-
Node
huaweimadrid-al00a_firmwareRange<9.1.0.261\(c00e120r4p1\)
AND
huaweimadrid-al00aMatch-
Node
huaweiparis-l29b_firmwareRange<9.1.0.380\(c636e1r1p3t8\)
AND
huaweiparis-l29bMatch-
Node
huaweiprinceton-al10b_firmwareRange<10.0.0.194\(c00e61r4p11\)
AND
huaweiprinceton-al10bMatch-
Node
huaweisydney-al00_firmwareRange<9.1.0.237\(c00e80r1p7t8\)
AND
huaweisydney-al00Match-
Node
huaweisydney-tl00_firmwareRange<9.1.0.237\(c01e80r1p7t8\)
AND
huaweisydney-tl00Match-
Node
huaweisydneym-al00_firmwareRange<10.0.0.159\(c00e64r1p5\)
AND
huaweisydneym-al00Match-
Node
huaweitony-al00b_firmwareRange<10.1.0.137\(c00e137r2p11\)
AND
huaweitony-al00bMatch-
Node
huaweitony-tl00b_firmwareRange<10.0.0.196\(c01e65r2p11\)
AND
huaweitony-tl00bMatch-
Node
huaweiyale-al00a_firmwareRange<10.0.0.196\(c00e62r8p12\)
AND
huaweiyale-al00aMatch-
Node
huaweiyale-l21a_firmwareRange<10.0.0.202\(c10e3r3p2\)
AND
huaweiyale-l21aMatch-
Node
huaweiyalep-al10b_firmwareRange<10.0.0.194\(c00e62r8p12\)
AND
huaweiyalep-al10bMatch-
Node
huaweicolumbia-l29d_firmwareRange<10.0.0.177\(c432e3r1p4\)
AND
huaweicolumbia-l29dMatch-
Node
huaweihonor_20_pro_firmwareRange<10.0.0.202\(c10e3r3p2\)
AND
huaweihonor_20_proMatch-
Node
huaweiy6_2019_firmwareRange<9.1.0.290\(c431e1r1p8\)
AND
huaweiy6_2019Match-
Node
huaweiy6_2019_firmwareRange<9.1.0.290\(c605e6r1p6\)
AND
huaweiy6_2019Match-
Node
huaweiy6_2019_firmwareRange<9.1.0.295\(c431e5r2p2\)
AND
huaweiy6_2019Match-
Node
huaweihonor_8a_firmwareRange<9.1.0.291\(c432e5r2p1\)
AND
huaweihonor_8aMatch-
Node
huaweihonor_8a_firmwareRange<9.1.0.291\(c636e4r4p1\)
AND
huaweihonor_8aMatch-
Node
huaweihonor_8a_firmwareRange<9.1.0.297\(c605e4r4p2\)
AND
huaweihonor_8aMatch-
Node
huaweihonor_view_20_firmwareRange<10.0.0.200\(c185e3r3p3\)
AND
huaweihonor_view_20Match-
Node
huaweihonor_view_20_firmwareRange<10.0.0.201\(c10e5r4p3\)
AND
huaweihonor_view_20Match-
VendorProductVersionCPE
googleandroid-cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
huaweiberkeley-l09_firmware*cpe:2.3:o:huawei:berkeley-l09_firmware:*:*:*:*:*:*:*:*
huaweiberkeley-l09-cpe:2.3:h:huawei:berkeley-l09:-:*:*:*:*:*:*:*
huaweicolumbia-al10b_firmware*cpe:2.3:o:huawei:columbia-al10b_firmware:*:*:*:*:*:*:*:*
huaweicolumbia-al10b-cpe:2.3:h:huawei:columbia-al10b:-:*:*:*:*:*:*:*
huaweicolumbia-l29d_firmware*cpe:2.3:o:huawei:columbia-l29d_firmware:*:*:*:*:*:*:*:*
huaweicolumbia-l29d-cpe:2.3:h:huawei:columbia-l29d:-:*:*:*:*:*:*:*
huaweicolumbia-tl00b_firmware*cpe:2.3:o:huawei:columbia-tl00b_firmware:*:*:*:*:*:*:*:*
huaweicolumbia-tl00b-cpe:2.3:h:huawei:columbia-tl00b:-:*:*:*:*:*:*:*
huaweicolumbia-tl00d_firmware*cpe:2.3:o:huawei:columbia-tl00d_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 571

CNA Affected

[
  {
    "product": "Android",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Android kernel"
      }
    ]
  }
]

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.6%