Lucene search

K
cveMediaTekCVE-2023-32873
HistoryMay 06, 2024 - 3:15 a.m.

CVE-2023-32873

2024-05-0603:15:09
CWE-787
MediaTek
web.nvd.nist.gov
33
20
vulnerability
keyinstall
out of bounds
write
privilege escalation
patch id
issue id

AI Score

7

Confidence

High

EPSS

0

Percentile

9.0%

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08583919; Issue ID: ALPS08304227.

Affected configurations

Vulners
Node
googleandroidRange<12.0
OR
googleandroidRange<13.0
OR
googleandroidRange<14.0
OR
mediatekmt6761_firmware
OR
mediatekmt6765_firmware
OR
mediatekmt6768_firmware
OR
mediatekmt6833_firmware
OR
mediatekmt6853_firmware
OR
mediatekmt6855_firmware
OR
mediatekmt6893_firmware
OR
mediatekmt6895_firmware
OR
mediatekmt6983_firmware
OR
mediatekmt8321_firmware
OR
mediatekmt8385_firmware
OR
mediatekmt8755_firmware
OR
mediatekmt8765_firmware
OR
mediatekmt8766_firmware
OR
mediatekmt8768_firmware
OR
mediatekmt8771_firmware
OR
mediatekmt8781_firmware
OR
mediatekmt8786_firmware
OR
mediatekmt8788_firmware
OR
mediatekmt8789_firmware
OR
mediatekmt8791t_firmware
OR
mediatekmt8792_firmware
OR
mediatekmt8795t_firmware
OR
mediatekmt8796_firmware
VendorProductVersionCPE
googleandroid*cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
mediatekmt6761_firmware*cpe:2.3:a:mediatek:mt6761_firmware:*:*:*:*:*:*:*:*
mediatekmt6765_firmware*cpe:2.3:a:mediatek:mt6765_firmware:*:*:*:*:*:*:*:*
mediatekmt6768_firmware*cpe:2.3:a:mediatek:mt6768_firmware:*:*:*:*:*:*:*:*
mediatekmt6833_firmware*cpe:2.3:a:mediatek:mt6833_firmware:*:*:*:*:*:*:*:*
mediatekmt6853_firmware*cpe:2.3:a:mediatek:mt6853_firmware:*:*:*:*:*:*:*:*
mediatekmt6855_firmware*cpe:2.3:a:mediatek:mt6855_firmware:*:*:*:*:*:*:*:*
mediatekmt6893_firmware*cpe:2.3:a:mediatek:mt6893_firmware:*:*:*:*:*:*:*:*
mediatekmt6895_firmware*cpe:2.3:a:mediatek:mt6895_firmware:*:*:*:*:*:*:*:*
mediatekmt6983_firmware*cpe:2.3:a:mediatek:mt6983_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 251

CNA Affected

[
  {
    "vendor": "MediaTek, Inc.",
    "product": "MT6761, MT6765, MT6768, MT6833, MT6853, MT6855, MT6893, MT6895, MT6983, MT8321, MT8385, MT8755, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8792, MT8795T, MT8796",
    "versions": [
      {
        "version": "Android 12.0, 13.0, 14.0",
        "status": "affected"
      }
    ]
  }
]

Social References

More

AI Score

7

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-32873