Vulnerability Description
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediatek | Lr11 | - |
| Mediatek | Lr12 | - |
| Mediatek | Lr12A | - |
| Mediatek | Lr13 | - |
| Mediatek | Lr9 | - |
| Mediatek | Nr15 | - |
| Mediatek | Nr16 | - |
| Mediatek | Mt2731 | - |
| Mediatek | Mt2735 | - |
| Mediatek | Mt6297 | - |
| Mediatek | Mt6725 | - |
| Mediatek | Mt6735 | - |
| Mediatek | Mt6737 | - |
| Mediatek | Mt6739 | - |
| Mediatek | Mt6750 | - |
| Mediatek | Mt6750S | - |
| Mediatek | Mt6755 | - |
| Mediatek | Mt6757 | - |
| Mediatek | Mt6757P | - |
| Mediatek | Mt6758 | - |
Related Weaknesses (CWE)
References
- https://corp.mediatek.com/product-security-bulletin/July-2022Vendor Advisory
- https://corp.mediatek.com/product-security-bulletin/July-2022Vendor Advisory
FAQ
What is CVE-2022-20083?
CVE-2022-20083 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileg...
How severe is CVE-2022-20083?
CVE-2022-20083 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-20083?
Check the references section above for vendor advisories and patch information. Affected products include: Mediatek Lr11, Mediatek Lr12, Mediatek Lr12A, Mediatek Lr13, Mediatek Lr9.