Vulnerability Description
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 7.2 | |
| Lg | Cv1 | - |
| Lg | Cv1S | - |
| Lg | Cv3 | - |
| Lg | Cv5 | - |
| Lg | Cv7 | - |
| Lg | Cv7As | - |
| Lg | Dh10 | - |
| Lg | Dh15 | - |
| Lg | Dh30 | - |
| Lg | Dh35 | - |
| Lg | Dh40 | - |
| Lg | Dh5 | - |
| Lg | Dh50 | - |
| Lg | G6 | - |
| Lg | G7 | - |
| Lg | G8 | - |
| Lg | K20 | - |
| Lg | K30 | - |
| Lg | K40 | - |
References
- https://lgsecurity.lge.com/Vendor Advisory
- https://lgsecurity.lge.com/Vendor Advisory
FAQ
What is CVE-2020-13842?
CVE-2020-13842 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (J...
How severe is CVE-2020-13842?
CVE-2020-13842 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13842?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Lg Cv1, Lg Cv1S, Lg Cv3, Lg Cv5.