Vulnerability Description
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 7.2 | |
| Lg | Cv1 | - |
| Lg | Cv1S | - |
| Lg | Cv3 | - |
| Lg | Cv5 | - |
| Lg | Cv7 | - |
| Lg | Cv7As | - |
| Lg | Dh10 | - |
| Lg | Dh15 | - |
| Lg | Dh30 | - |
| Lg | Dh35 | - |
| Lg | Dh40 | - |
| Lg | Dh5 | - |
| Lg | Dh50 | - |
| Lg | G6 | - |
| Lg | G7 | - |
| Lg | G8 | - |
| Lg | K20 | - |
| Lg | K30 | - |
| Lg | K40 | - |
Related Weaknesses (CWE)
References
- https://lgsecurity.lge.com/Vendor Advisory
- https://lgsecurity.lge.com/Vendor Advisory
FAQ
What is CVE-2020-13839?
CVE-2020-13839 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200...
How severe is CVE-2020-13839?
CVE-2020-13839 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13839?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Lg Cv1, Lg Cv1S, Lg Cv3, Lg Cv5.